CVE-2023-2861 — Improper Access Control in Qemu
Severity
7.1HIGHNVD
CNA6.0OSV3.2
EPSS
0.0%
top 87.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
1
Timeline
PublishedDec 6
Latest updateApr 13
Description
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2