HIGH · 7.6

CVE-2016-9602

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder a...

Vulnerability Description

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

CVSS Score

7.6

HIGH

CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QemuQemu< 2.9
DebianDebian Linux8.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-9602?

CVE-2016-9602 is a vulnerability with a CVSS score of 7.6 (HIGH). Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder a...

How severe is CVE-2016-9602?

CVE-2016-9602 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-9602?

Check the references section above for vendor advisories and patch information. Affected products include: Qemu Qemu, Debian Debian Linux.