Impact
A race condition (CWE-362) between the vncproxy and vncwebsocket API calls allows an attacker with privileged access to invoke vncproxy and hijack a VNC session that a different authenticated user has established for another virtual machine. Successful hijacking grants the attacker visibility into, and control over, the victim’s VM, thereby compromising confidentiality and integrity of virtual machine data and potentially the host system.
Affected Systems
Proxmox Virtual Environment 9.x and 8.x are affected. The pve-manager component is vulnerable when older than v9.1.9 for 9.x or older than v8.4.19 for 8.x. The qemu-server component is impacted if older than v9.1.7 for 9.x or older than v8.4.7 for 8.x. The pve-container component is vulnerable when older than v6.1.3 for 9.x or older than v5.3.4 for 8.x.
Risk and Exploitability
The identified flaw has a CVSS score of 7.2, indicating high severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation under current conditions. It is not listed in the CISA KEV catalog. Attackers would typically need authenticated access to the Proxmox management interface, either locally or over the network, to call the vncproxy API. If the vulnerability is exploited, the attacker obtains full control over the target VM via the hijacked VNC session.
OpenCVE Enrichment