CAS-003 · Question #516
An organization is implementing a virtualized thin-client solution for normal user computing and access. During a review of the architecture, concerns were raised that an attacker could gain access…
The correct answer is C. One virtual environment may have one or more application-layer vulnerabilities, which could allow. In a virtualized thin-client architecture, all users share the same underlying hypervisor and often the same application stack or shared services. If one virtual environment contains application-layer vulnerabilities - particularly in shared components such as the hypervisor…
Question
An organization is implementing a virtualized thin-client solution for normal user computing and access. During a review of the architecture, concerns were raised that an attacker could gain access to multiple user environments by simply gaining a foothold on a single one with malware. Which of the following reasons BEST explains this?
Options
- AMalware on one virtual environment could enable pivoting to others by leveraging vulnerabilities
- BA worm on one virtual environment could spread to others by taking advantage of guest OS
- COne virtual environment may have one or more application-layer vulnerabilities, which could allow
- DMalware on one virtual user environment could be copied to all others by the attached network
How the community answered
(61 responses)- A7% (4)
- B16% (10)
- C74% (45)
- D3% (2)
Explanation
In a virtualized thin-client architecture, all users share the same underlying hypervisor and often the same application stack or shared services. If one virtual environment contains application-layer vulnerabilities - particularly in shared components such as the hypervisor, shared libraries, or management interfaces - an attacker who exploits those vulnerabilities can break out of the isolated environment and gain access to co-located virtual machines. This is the VM escape / hypervisor vulnerability threat model. The shared nature of the infrastructure means a single application-layer flaw is a systemic risk across all hosted environments.
Topics
Community Discussion
No community discussion yet for this question.