CVE-2023-0664

HIGH

QEMU Guest Agent - Privilege Escalation

Title source: llm
STIX 2.1

Description

A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 6.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-250
Status published
Products (5)
fedoraproject/fedora 37
qemu/qemu < 8.0.0
redhat/enterprise_linux 7.0
redhat/enterprise_linux 8.0
redhat/enterprise_linux 9.0
Published Mar 29, 2023
Tracked Since Feb 18, 2026