Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23569
HistoryApr 10, 2020 - 12:30 a.m.

Arbitrary Code Execution

2020-04-1000:30:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

EPSS

0

Percentile

10.3%

libvirt is vulnerable to arbitrary code execution. The vulnerability exists as libvirt_proxy, a setuid helper application allowing non-privileged users to communicate with the hypervisor, was discovered to not properly validate user requests. Local users could use this flaw to cause a stack-based buffer overflow in libvirt_proxy, possibly allowing them to run arbitrary code with root privileges.