CVE-2017-7471: Critical severity Qemu Qemu vulnerability

Published Jul 9, 2018
·
Updated

Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host directory. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

Affected Software

6 affected components
Qemu Qemu<=2.8.1.1
Qemu Qemu=2.9.0-rc0
Qemu Qemu=2.9.0-rc1
Qemu Qemu=2.9.0-rc2
Qemu Qemu=2.9.0-rc3
Qemu Qemu=2.9.0-rc4

Event History

Jul 9, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2017-7471?

CVE-2017-7471 has been rated as a medium severity vulnerability due to its impact on host file system access.

2

How do I fix CVE-2017-7471?

To fix CVE-2017-7471, upgrade QEMU to version 2.9.0 or later.

3

Who is affected by CVE-2017-7471?

Any privileged user inside a guest running affected versions of QEMU can exploit CVE-2017-7471.

4

What is the impact of CVE-2017-7471?

The impact of CVE-2017-7471 allows a guest user to access and manipulate files on the host file system.

5

When was CVE-2017-7471 disclosed?

CVE-2017-7471 was disclosed in April 2017.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203