cbcvebase.
CVE-2017-7471
published 2018-07-09

CVE-2017-7471: Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue…

PriorityP342critical9CVSS 3.1
AVAACLPRLUINSCCHIHAH
EPSS
0.85%
54.3th percentile
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host directory. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:2.8+dfsg-5 (bookworm)qemu 1:2.8+dfsg-5 (bookworm)
qemuqemu<= 2.8.1.1
qemuqemu
qemuqemu>= 0 < 1:2.8+dfsg-51:2.8+dfsg-5
qemuqemu>= 0 < 1:2.8+dfsg-51:2.8+dfsg-5
qemuqemu>= 0 < 1:2.8+dfsg-51:2.8+dfsg-5
qemuqemu>= 0 < 1:2.8+dfsg-51:2.8+dfsg-5

CVSS provenance

nvdv3.19.0CRITICALCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.7HIGHAV:A/AC:L/Au:S/C:C/I:C/A:C
osv9.0CRITICAL
vendor_debian9.0CRITICAL
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.