Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24849
HistoryApr 10, 2020 - 1:07 a.m.

Arbitrary Code Execution

2020-04-1001:07:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.051 Low

EPSS

Percentile

93.0%

qemu-kvm is vulnerable to arbitrary code execution. The vulnerability exists as a flaw was found in the way qemu-kvm handled VSC_ATR messages when a guest was configured for a CCID (Chip/Smart Card Interface Devices) USB smart card reader in passthrough mode. An attacker able to connect to the port on the host being used for such a device could use this flaw to crash the qemu-kvm process on the host or, possibly, escalate their privileges on the host.