CVE-2015-3456 "VENOM" vulnerability

CVE-2015-3456 "VENOM" vulnerability


The VENOM (Virtualized Environment Neglected Operations Manipulation) vulnerability impacts popular virtualization platforms, including QEMU, Xen, KVM, and Oracle's VirtualBox.
It consists in a buffer overflow condition in the FDC (Floppy Disk Controller) emulation code.
Fortinet virtual appliances including FortiOS, FortiManager, FortiAnalyzer and any other product running on Hyper-V, Xen and KVM are not affected.


Guest VM DoS and VM escape

Affected Products

FortiSandbox 2.0.2 and below is theoretically affected, however no working exploit code has been known to be available so far.


Upgrade to FortiSandbox 2.0.3.