HomeSecuritykvmCTF: Google's new VRP program for finding zero-day KVM vulnerabilities

kvmCTF: Google's new VRP program for finding KVM zero-day vulnerabilities

Google is launching kvmCTF , a new vulnerability reward program (VRP), first announced in October 2023, aimed at strengthening the security of its Kernel-based Virtual Machine (KVM) hypervisor . The company said that under this VRP program, it will award up to $250,000 to researchers who discover and report complete VM escape exploits.

kvmCTF Google VRP zero-day vulnerabilities

KVM (open-source hypervisor) is a critical component in consumer and enterprise settings, powering the Android and Google Cloud.

As an active and key contributor to KVM, Google developed kvmCTF to help identify and fix vulnerabilities, strengthening its security.

See also: Cisco fixes zero-day vulnerability in NX-OS

Like Google's kernelCTF bounty program, which targets security , kvmCTF focuses on flaws in the Kernel-based Virtual Machine (KVM) hypervisor, which are accessible from VMs.

The goal is to perform successful guest-to-host attacks. QEMU or host-to-KVM vulnerabilities will not receive rewards.

Security researchers participating in Google's kvmCTF program will have a controlled lab environment where they can use their exploits to identify vulnerabilities. However, unlike other similar programs, kvmCTF focuses on zero-day vulnerabilities rather than known bugs.

Zero-day vulnerabilities are security holes that have not been discovered or patched by software vendors. The term 'zero-day' refers to the fact that developers have zero days to fix the problem before it is exploited by malicious users.

See also: Hackers exploit vulnerability in D-Link DIR-859 routers

Zero-day vulnerabilities are particularly dangerousbecause there are no updates or patches available to address them. This means that users and organizations are vulnerable to attacks until the vulnerability.

The importance of zero-day vulnerabilities lies in the fact that they can be used to perform malicious actions such as stealing data, installing malware, or gaining unauthorized access to systems. These attacks can have serious consequences for the security and privacy of users.

Detecting and addressing zero-day vulnerabilities is critical to system security. That's why technology like Google invest significant amounts of money in discovering and fixing these vulnerabilities, offering rewards to security researchers who find them.

Google kvmCTF: The reward levels are:

  • Full VM escape: $250,000
  • Arbitrary memory write: $100,000
  • Arbitrary memory read: $50,000
  • Relative memory write-down: $50,000
  • Denial of service: $20,000
  • Relative memory read: $10,000
kvmCTF: Google's new VRP program for finding KVM zero-day vulnerabilities

The kvmCTF infrastructure is hosted in Google's Bare Metal Solution (BMS) environment

Security researchers will gain access to the Guest VM and attempt to perform a guest-to-host attack. The goal of the attack is to exploit a zero-day vulnerability in the KVM subsystem of the host kernel.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Juniper Networks patches serious “auth bypass” vulnerability

“If the attack is successful, the attacker will receive a flag proving their achievement in exploiting the vulnerability. The severity of the attack will determine the amount of the reward, which will be based on the reward tier system explained above. All reports will be thoroughly evaluated on a case-by-case basis,” said software engineer Marios Pomonis.

Participants should review the kvmCTF rules before launching their attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS