#VU17772 Command injection in Virtual Desktop Server Manager - CVE-2019-3831
Published: February 19, 2019
Virtual Desktop Server Manager
oVirt
Description
The vulnerability allows a local high-privileged attacker to execute arbitrary code on the target system.
The vulnerability exists due to exposure of exposed a systemd_run() function to the vdsm system use. A local attacker can inject arbitrary commands and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.