CVE-2013-2007 describes a local privilege escalation vulnerability in the Qemu guest agent (versions 1.4.1 and earlier), specifically when used by Xen and operating in daemon mode. The agent uses weak file permissions, allowing local users to read and write to sensitive files. With a CVSS score of 6.9, this vulnerability has a local attack vector, medium attack complexity, and high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or Metasploit/Nuclei modules, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.1CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:1.4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.