CVE-2013-2231
Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, and Workstation Supplementary 6, when installing on Windows, allows local users to gain privileges via a crafted program in an unspecified folder.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- redhat/enterprise linux · redhat/enterprise linux desktop supplementary · redhat/enterprise linux server supplementary · redhat/enterprise linux workstation supplementary
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-1100.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1101.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=980757
- http://rhn.redhat.com/errata/RHSA-2013-1100.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1101.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=980757
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.