CVE-2018-20621

HIGH

Microvirt Memu - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

An issue was discovered in Microvirt MEmu 6.0.6. The MemuService.exe service binary is vulnerable to local privilege escalation through binary planting due to insecure permissions set at install time. This allows code to be run as NT AUTHORITY/SYSTEM.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2018-20621

Scores

CVSS v3 7.8
EPSS 0.0056
EPSS Percentile 68.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
microvirt/memu 6.0.6
Published Mar 13, 2019
Tracked Since Feb 18, 2026