Vulnerability Intelligence Report
CVE-2019-12928
The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's -qmp interface is meant to be used by trusted users. If one is able to access this interface via a tcp socket open to the internet, then it is an insecure configuration issue
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:23.04%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| No affected products specified. | ||
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
23.036%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2019-06-20T00:00:00 |
| Published | 2019-06-24T10:06:44 |
| Last Updated | 2024-08-04T23:32:55 |
Community Chatter & Buzz