Resource management error in Xen - CVE-2014-7188

 

Resource management error in Xen - CVE-2014-7188

Published: October 2, 2014 / Updated: July 28, 2020


Vulnerability identifier: #VU32490
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2014-7188
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: Xen Project
Affected software:
Xen

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.


How to mitigate CVE-2014-7188

Install update from vendor's website.

Sources