CVE-2019-10166
If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- redhat/libvirt · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · redhat/virtualization
- Source
- secalert@redhat.com
References
- https://access.redhat.com/libvirt-privesc-vulnerabilitiesVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10166Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/202003-18Third Party Advisory
- https://access.redhat.com/libvirt-privesc-vulnerabilitiesVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10166Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/202003-18Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.