The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.