Improper Access Control Vulnerability in Qemu VirtFS with Plan 9 File System (9pfs) Support

Improper Access Control Vulnerability in Qemu VirtFS with Plan 9 File System (9pfs) Support

CVE-2017-7493 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest.

Learn more about our User Device Pen Test.