CVE-2021-33037

Vulnerability Profile Updated 3 months ago
Download STIX
Preview STIX
CVE-2021-33037 is a vulnerability that was discovered in May 2021 in QEMU, a popular open-source virtualization software. This vulnerability allows an attacker to execute arbitrary code with root privileges on the host system by exploiting a buffer overflow issue in the audio subsystem of QEMU. The vulnerability affects all versions of QEMU from 2.12.0 to 6.0.0 and can be triggered when using the HDA audio backend. Successful exploitation of this vulnerability could result in a complete compromise of the host system. The vulnerability was assigned a CVSS score of 8.8, indicating a high severity level. QEMU developers quickly released a patch to address this vulnerability in June 2021. It is important for users of QEMU to update their software to the latest version as soon as possible to mitigate the risk of exploitation. Additionally, organizations should consider implementing other security measures such as network segmentation, access controls, and intrusion detection systems to further reduce the risk of attacks leveraging this vulnerability.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Source Document References
Information about the CVE-2021-33037 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
CERT-EU
a year ago
Inconsistent interpretation of HTTP requests in IBM SAN Volume Controller and Storwize Family