Virtualization Escape
Description
The adversary pivots across partitions by abusing the mechanisms a separation kernel or hypervisor exposes for inter-partition communication and device sharing. Paths include message ports/queues, shared-memory windows, virtual NICs and bridges, hypercalls, and common driver backends (e.g., storage or DMA engines without strict IOMMU bounds). A foothold in a less-trusted partition, often a payload or guest OS, can be turned into access to a higher-privilege domain by crafting traffic that exploits parser flaws in port services, racing management channels, or coercing backend drivers to perform out-of-bounds operations. Once the boundary is crossed, the actor can reach bus gateways, file systems, or control applications hosted in adjacent partitions and continue movement under the guise of permitted inter-partition exchanges.
Mappings
EU regulation articles
Inter-partition communication channels (message ports, shared memory, virtual NICs, hypercalls) ARE the attack surface (2)(j)'s obligation requires the product to limit and harden.
Hypervisor-escape via parser flaws or driver out-of-bounds is the canonical exploitation scenario (2)(k)'s exploitation-mitigation obligation (IOMMU, capability checks, hardened parsers) is meant to reduce the impact of.
Effective and regular tests of separation-kernel/hypervisor boundaries (fuzzing of message ports, IOMMU validation) is the (Part II, 3) obligation manufacturers must apply for products relying on virtualization separation.
Hypervisor-escape testing (primary: Art. 88(1)) — separation-kernel boundary fuzzing — is reviewed under 76(6)'s effectiveness-assessment-policy.
Hypervisor escape attacks the integrity boundary 84(2)'s Annex VII point 5.1 requires for separation kernels and partitioned environments.
Hypervisor/separation-kernel boundary testing — fuzzing of message ports, IOMMU validation — is within 88(1)'s testing programme scope.
Hypervisor-escape testing (primary: Art. 88(1)) cascades to 88(3) — TLPT 3-yearly cadence covers separation-kernel boundary fuzzing on operator products.
Separation kernels, hypervisors, virtual NICs, IPC port services, and shared driver backends with IOMMU bounds are squarely within Art. 21(2)(e)'s network-and-information-systems acquisition/development/maintenance and vulnerability-handling obligation — including disclosed parser flaws and racing-management-channel weaknesses.
Inter-partition communication ports, shared-memory windows, hypercalls, and DMA-engine permissions are access-controlled isolation boundaries; Art. 21(2)(i)'s access-control + asset-management obligation governs which partitions can invoke which inter-partition mechanisms.
Vulnerability-handling-and-disclosure procedures must apply to hypervisor and separation-kernel defects; coordinated remediation is the procedural mechanism that closes virtualization-escape paths once disclosed.
Separation kernels and hypervisors are produced through the secure-development life cycle; the rules for that lifecycle govern the implementation quality of inter-partition communication, shared-memory windows and device-emulation paths that virtualization escape exploits.
Security-patch management procedures determine how quickly hypervisor defects are deployed in flight or ground systems; deployment cadence bounds the exploit window for disclosed escape paths.
ENISA controls
Coding standards including safe memory access reduce parser-flaw and out-of-bounds-write defects in port services and management channels.
A documented secure development lifecycle covers separation-kernel and hypervisor design including IOMMU-bounded driver backends and hardened message-port services.
Cross-reference controls
Mapped by SPARTA, not curated by SafeMode Space.
T1611 'Escape to Host' is the exact-concept ATT&CK technique for breaking out of a virtualisation/container boundary to the host; SPARTA LM-0005 'Virtualization Escape' covers TSP/partition escape on spacecraft hypervisors. Cross-tactic moderate because T1611 sits in privilege-escalation while SPARTA LM-0005 is lateral-movement (the activity is the same; ATT&CK frames it as priv-esc, SPARTA frames it as lateral).
Escaping a virtualised partition to reach the host is the failure mode domain separation exists to prevent, and the practice requires domain separation for the on-board architecture. Moderate rather than high because the practice states the principle rather than the enforcement mechanism whose defect the escape exploits.
AC-3 mitigates LM-0005 by enforcing access authorization on hypervisor and inter-partition interfaces.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8323r1, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
T1611 'Escape to Host' explicitly covers overcoming container/hypervisor fences to gain host access — direct match to LM-0005's virtualization escape from less-trusted partition to higher-privilege domain.
- space-shieldT2017Compromise of another partition in Time and Space Partitioning OS or other types of satellite hypervisorsaddresseshigh
T2017 'Compromise of another partition in Time and Space Partitioning OS or other types of satellite hypervisors' is a direct cross-framework counterpart of LM-0005 — both describe pivoting across hypervisor partitions through ports allowed by the hypervisor.
T2046.002 'Inter-Application Compromise' explicitly covers hypervisor-environment guest-application escape that breaks the spatial isolation promise — direct match to LM-0005's virtualization escape via inter-partition exchanges.
SPARTA countermeasures
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Cite as SafeMode Space, LM-0005 (SPARTA v3.2).