Qubes OS fixed a vulnerability in qvm-copy-to-vm that could let an attacker execute arbitrary commands in the privileged Dom0 administrative domain through a specially crafted file name. Because Dom0 manages the isolated virtual machines, successful exploitation could result in full compromise of the host’s security boundary.
The flaw occurred when the file-transfer utility invoked localized kdialog or zenity dialogs via system() and passed attacker-controlled file and VM names into the command line. Validation did not safely handle certain non-ASCII characters, allowing shell metacharacters such as backticks and dollar signs to reach the shell; the fix is included in qubes-core-dom0-linux version 4.3.22.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Qubes OS fixed a vulnerability in qvm-copy-to-vm that could allow a crafted non-ASCII filename containing shell metacharacters to execute commands in the privileged Dom0 domain when localized kdialog or zenity dialogs were invoked through system(). The fix was released in qubes-core-dom0-linux version 4.3.22.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
opennet.ru
Open sourceopennet.me
Open sourcegithub.com
Open sourcequbes-os.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.