CVE-2020-35517: Qemu
High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.
Affected products
- Qemu Qemu: from 5.0.0, up to and including 5.2.50
Published 2021-01-28. Last modified 2026-06-17.