Privilege Escalation Vulnerability in QEMU Virtio-FS Daemon
CVE-2022-0358

7.8HIGH

Key Information:

Vendor

Qemu

Vendor
CVE Published:
29 August 2022

What is CVE-2022-0358?

A vulnerability exists in the QEMU virtio-fs shared file system daemon where a local guest user can create files in shared directories with unintended group ownership. This occurs when a directory is set with SGID for a specific group and is writable by users outside of that group. Exploiting this flaw can enable an unprivileged user within the guest system to access resources intended for the root group, leading to potential privilege escalation. Additionally, a malicious local user could misuse the executable file created within the guest to escalate privileges on the host system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

QEMU/virtiofsd Fixed in qemu v6.2.0-7

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.