CVE-2017-7471 describes an improper access control vulnerability in QEMU when using VirtFS for host directory sharing. A privileged guest user could exploit this flaw to access files outside the designated shared folder on the host system, potentially leading to privilege escalation. With a CVSS score of 9.0 (CRITICAL), this vulnerability has a low attack complexity and can result in high impact to confidentiality, integrity, and availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in the KEV catalog, indicating it is not actively exploited. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.8.1.1CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
2.9.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:2.9.0:rc0:*:*:*:*:*:* | ||
2.9.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:2.9.0:rc1:*:*:*:*:*:* | ||
2.9.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:2.9.0:rc2:*:*:*:*:*:* | ||
2.9.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:2.9.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.3 Reddit, 0.3 Bluesky, 0.4 Mastodon, and 2.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.9 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.