Impact
An insufficient check allows overwriting arbitrary files through a symlink, enabling a guest user to overwrite host‑side files and elevate privileges. The flaw can lead to full host compromise and is classified as CWE‑59. This provides attackers the ability to modify system configuration or binaries, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Webpros SolusVM; no specific version range is disclosed, so all current installations are considered vulnerable until patched.
Risk and Exploitability
The CVSS score is 9.4, indicating critical severity. The EPSS score is in the < 1% range, suggesting a low probability of exploitation, and it is not listed in the CISA KEV catalog. Likely the attack requires guest access to a directory that the host monitors for symlink resolution, whereby a crafted symlink can point to a privileged file; the exploiter then overwrites it, achieving host‑level access. This path is not externally exposed but can be leveraged if the host allows symlinks from guest paths.
OpenCVE Enrichment