BadUpdate and BadAvatar work by using a bruteforce attack against the hypervisor's memory encryption library and using that to insert a function pointer to arbitrary code. The memory write relies on a race condition because the vulnerable area is cached at Level 2. I am greatly oversimplifying...