The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.
2021-10-01T03:15:06.913
2024-11-21T06:22:00.840
Modified
CVSSv3.1: 8.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | canonical | multipass | < 1.7.0 | Yes |
Operating System | microsoft | windows | - | No |