The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/canonical/multipass/pull/2150 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: canonical
Published: 2021-10-01T02:35:19.696506Z
Updated: 2024-09-17T03:23:37.922Z
Reserved: 2021-06-29T00:00:00
Link: CVE-2021-3626
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-10-01T03:15:06.913
Modified: 2024-11-21T06:22:00.840
Link: CVE-2021-3626
Redhat
No data.