← back
CVE-2020-25637

CVE-2020-25637

EPSS 0.5%CWE-415
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
06 Oct 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash the libvirt daemon, resulting in a denial of service, or potentially escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected products
n/a · libvirt

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →