CVE-2018-20621: High severity memu vulnerability
Published Mar 13, 2019
·Updated
An issue was discovered in Microvirt MEmu 6.0.6. The MemuService.exe service binary is vulnerable to local privilege escalation through binary planting due to insecure permissions set at install time. This allows code to be run as NT AUTHORITY/SYSTEM.
Affected Software
1 affected component
Microvirt MEmu=6.0.6
Event History
Mar 13, 2019
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20621?
CVE-2018-20621 has a high severity due to its potential for local privilege escalation.
2
How do I fix CVE-2018-20621?
To fix CVE-2018-20621, ensure that the MemuService.exe service binary has secure permissions and update to the latest version of MEmu.
3
Who is affected by CVE-2018-20621?
Users of Microvirt MEmu version 6.0.6 are affected by CVE-2018-20621.
4
What type of vulnerability is CVE-2018-20621?
CVE-2018-20621 is a local privilege escalation vulnerability resulting from binary planting.
5
What can an attacker achieve with CVE-2018-20621?
An attacker exploiting CVE-2018-20621 can run arbitrary code with NT AUTHORITY/SYSTEM privileges.