CyberRota Analysis
AI-GeneratedA race condition vulnerability in the Proxmox Virtual Environment allows an authenticated attacker with access to the "vncproxy" API to hijack VNC sessions of other users connected to different virtual machines. This could lead to unauthorized access to sensitive data or control over the affected VMs. Organizations using affected versions of Proxmox should prioritize patching to mitigate this high-severity risk.
Original NVD Description
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM.