Back

MEDIUM

HVM guest VNC server allows compromise of entire host OS by any VNC console user

Published Mar 20, 2007

Description

The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrated by mapping files to a CDROM device. NOTE: some of these details are obtained from third party information.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 20, 2007
Updated Aug 7, 2024
Reserved Feb 16, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Mar 14, 2007