← volver
CVE-2020-25637

CVE-2020-25637

EPSS 0.5%CWE-415
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
06 oct 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash the libvirt daemon, resulting in a denial of service, or potentially escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Productos afectados
n/a · libvirt

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →