CVE-2021-3626

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
4.6
MEDIUM
Affected
1
PROJECT

Description

The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.

Multipass orchestrates virtual Ubuntu instances
GitHubGitHub
9.12K