CVE-2017-13672
MEDIUMQEMU < 2.10.2 - Denial of Service via VGA Display Update
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-13672. PoCs published by DavidBuchanan314.
AI-analyzed exploit summary This PoC exploits CVE-2017-13672, an out-of-bounds read vulnerability in the VGA Cirrus QEMU driver, leading to a denial-of-service (DoS) condition. The exploit manipulates VGA controller registers to trigger the vulnerability.
Description
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
Exploits (1)
This PoC exploits CVE-2017-13672, an out-of-bounds read vulnerability in the VGA Cirrus QEMU driver, leading to a denial-of-service (DoS) condition. The exploit manipulates VGA controller registers to trigger the vulnerability.
References (11)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H