Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7299
HistoryAug 15, 2018 - 3:27 a.m.

Code Execution Via Privilege Escalation

2018-08-1503:27:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.004

Percentile

73.3%

libvirt.so is vulnerable to privilege escalation. The vulnerability is possible because failure to check connect:write permission in the virConnectDomainXMLToNative function provides the attacker domain:write privileges to execute Qemu binaries through malicious XML.