This talk will look at hypervisors as an enduring vulnerability research target. To maintain working exploits, any enduring target needs a number of things that favour a research team: * The target has a complex code base and a large enough attack surface that the bug supply is sustainable * Attackers have the ability to interact with the target so that it makes reliable exploitation generally feasible (to perform heap grooming, use the results of infoleaks etc.) * The target has some useful effect to attackers when a security boundary is violated (privescs, hypervisor escapes, etc.) * The target has a level of ubiquity (i.e., an effect is generally of value) Silvio will discuss bugs that he and others at InfoSect have found in hypervisors.