BadAML: Exploiting Legacy Firmware Interfaces to Compromise Confidential Virtual Machines
Satoru Takekoshi, Manami Mori, Takaaki Fukai, Takahiro Shinagawa
Abstract
Confidential virtual machines (CVMs) are an emerging form of trusted execution environment that enable existing operating systems (OSs) to run securely without trusting cloud providers. To this end, CVMs employ hardware-based memory encryption for runtime confidentiality and cryptographic attestation to verify memory integrity at startup. However, we reveal a previously overlooked attack vector that allows malicious cloud providers to bypass CVM attestation and execute arbitrary code within users' CVMs regardless of specific CVM configurations. Our attack, BadAML, exploits the Advanced Configuration and Power Interface (ACPI), a legacy yet widely adopted firmware interface for machine configuration. Specifically, BadAML leverages ACPI Machine Language (AML) to inject arbitrary binary code into the guest OS kernel without affecting CVM attestation. Because ACPI remains an essential component even in virtualized environments, BadAML constitutes a powerful and portable attack vector independent of guest OS type and CVM technology. We demonstrate proof-of-concept exploits of BadAML in both Linux and Windows CVM environments. We then analyze possible mitigation measures, discussing their effectiveness and limitations. Finally, we introduce AML sandboxing, a practical defense that restricts memory access to safe regions under the CVM threat model; we present its design, implementation, and evaluation, demonstrating its effectiveness across 18 real-world cloud CVM instances.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang et al.ASPLOS 2023 · 12 citations
- Exploiting Unprotected I/O Operations in AMD's Secure Encrypted VirtualizationMengyuan Li, Yinqian Zhang, Zhiqiang Lin, Yan SolihinUSENIX Security 2019 · 104 citations
- Core slicing: closing the gap between leaky confidential VMs and bare-metal cloudZiqiao Zhou, Yizhou Shan, Weidong Cui, Xinyang Ge et al.OSDI 2023 · 12 citations
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi et al.USENIX Security 2024 · 48 citations
- Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual MachinesChuqi Zhang, Rahul Priolkar, Yuancheng Jiang, Yuan Xiao et al.EuroSys 2025 · 4 citations
