Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.
2018-04-26T19:29:00.230
2024-11-21T03:01:29.523
Modified
CVSSv3.0: 7.6 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qemu | qemu | < 2.9 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |