CVE Vulnerabilities

CVE-2014-3689

Improper Privilege Management

Published: Nov 14, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
4 MODERATE
AV:A/AC:H/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
QemuQemu*2.1.3 (including)
QemuUbuntudevel*
QemuUbuntuesm-infra-legacy/trusty*
QemuUbuntutrusty*
QemuUbuntutrusty/esm*
QemuUbuntuutopic*
Qemu-kvmUbuntulucid*
Qemu-kvmUbuntuprecise*

Potential Mitigations

References