cbcvebase.
CVE-2016-9602
published 2018-04-26

CVE-2016-9602: Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access…

PriorityP351high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
3.79%
88.8th percentile
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianqemu< qemu 1:2.8+dfsg-3 (bookworm)qemu 1:2.8+dfsg-3 (bookworm)
qemuqemu< 2.92.9
qemuqemu>= 0 < 1:2.8+dfsg-31:2.8+dfsg-3
qemuqemu>= 0 < 1:2.8+dfsg-31:2.8+dfsg-3
qemuqemu>= 0 < 1:2.8+dfsg-31:2.8+dfsg-3
qemuqemu>= 0 < 1:2.8+dfsg-31:2.8+dfsg-3
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.332.0.0+dfsg-2ubuntu1.33
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.111:2.5+dfsg-5ubuntu10.11

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian7.6HIGH
vendor_redhat7.6HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.