CVE-2013-2007: Qemu
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.
Affected products
- Qemu Qemu: version 1.4.1 only
Published 2013-05-21. Last modified 2026-06-16.