CVE-2020-24165: High severity qemu vulnerability
DISPUTED An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID CVE-2020-24165?
The vulnerability ID CVE-2020-24165 refers to an issue in TCG Accelerator in QEMU 4.2.0 that allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
What is the severity of CVE-2020-24165?
The severity of CVE-2020-24165 is rated as high with a severity value of 8.8.
What software is affected by CVE-2020-24165?
The software affected by CVE-2020-24165 is QEMU version 4.2.0.
How can local attackers exploit CVE-2020-24165?
Local attackers can exploit CVE-2020-24165 to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
Is there a fix available for CVE-2020-24165?
Yes, a fix for CVE-2020-24165 is available. Please refer to the provided references for more information on how to apply the fix.