QEMU: local privilege escalation via the QEMU Guest Agent on Windows
Published Mar 29, 2023
7.8
HIGHCVSS 3.1
EPSS 0.31%
Description
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.
Affected products
- Vendor n/a Product QEMU Defaultn/a
- Version unknownStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | QEMU | n/a |
|
Configuration 2
- 7.0
- 8.0
- 9.0
Configuration 3
- 37
No data.
Red Hat Enterprise Linux 9
virtio-win-0:1.9.33-0.el9_2
Fixed · RHBA-2023:2451
Red Hat Enterprise Linux 7
virtio-win
Out of support scope
Red Hat Enterprise Linux 8
virtio-win
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | virtio-win-0:1.9.33-0.el9_2 | Fixed | RHBA-2023:2451 |
| Red Hat Enterprise Linux 7 | virtio-win | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | virtio-win | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw has been rated as having a security impact of Moderate. The flaw affects Windows VMs using virtio-win drivers with QEMU Guest Agent installed in the guest. This is not a VM escape vulnerability, meaning that it does not allow a malicious user to break out of the guest.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 18, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.31% (0.00306) | 21.18th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.31% (0.00308) | 22.24th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.02% (0.00016) | 1.77th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 16.02th | v3 (v2023.03.01) |
| Jul 3, 2024 | 0.04% (0.00045) | 14.36th | v3 (v2023.03.01) |
| Apr 8, 2023 | 0.04% (0.00042) | 5.68th | v3 (v2023.03.01) |
| Mar 30, 2023 | 0.04% (0.00045) | 12.20th | v3 (v2023.03.01) |
References (10)
- https://access.redhat.com/security/cve/CVE-2023-0664 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2167423 Issue TrackingPatchThird Party Advisory
- https://gitlab.com/qemu-project/qemu/-/commit/07ce178a2b0768eb9e712bb5ad0cf6dc7fcf0158 Patch
- https://gitlab.com/qemu-project/qemu/-/commit/88288c2a51faa7c795f053fc8b31b1c16ff804c5 Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MURWGXDIF2WTDXV36T6HFJDBL632AO7R/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SEOC7SRJWLZSXCND2ADFW6C76ZMTZLE4/ vendor-advisory
- https://lists.nongnu.org/archive/html/qemu-devel/2023-03/msg01445.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-0664
- https://security.netapp.com/advisory/ntap-20230517-0005/
- https://www.cve.org/CVERecord?id=CVE-2023-0664
Change history (0)
No recorded changes yet.