Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-35517

Опубликовано: 28 янв. 2021
Источник: nvd
CVSS3: 8.2
CVSS2: 4.6
EPSS Низкий

Описание

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.2.50 (включая)

EPSS

Процентиль: 6%
0.00027
Низкий

8.2 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-269
CWE-269

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 4 лет назад

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

CVSS3: 7.5
redhat
больше 4 лет назад

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

CVSS3: 8.2
debian
больше 4 лет назад

A flaw was found in qemu. A host privilege escalation issue was found ...

rocky
больше 4 лет назад

Important: virt:rhel and virt-devel:rhel security update

CVSS3: 8.2
github
около 3 лет назад

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

EPSS

Процентиль: 6%
0.00027
Низкий

8.2 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-269
CWE-269