Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12029
HistoryJan 15, 2019 - 9:11 a.m.

Arbitrary Code Execution

2019-01-1509:11:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.002 Low

EPSS

Percentile

51.6%

QEMU is vulnerable to arbitrary code execution. An out-of-bounds read/write access flaw was found in the way QEMU’s VGA emulation with VESA BIOS Extensions (VBE) support performed read/write operations using I/O port methods. A privileged guest user could use this flaw to execute arbitrary code on the host with the privileges of the host’s QEMU process.

References