Privilege escalation in Xen - CVE-2017-12855
Published: August 16, 2017
Vulnerability identifier: #VU7953
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12855
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker on the guest system to gain elevated privileges on the host system.
The weakness exists due to flaws when clearing grant status bits. A local attacker on a guest system may modify or reuse a grant that is still in use by another domain and obtain potentially sensitive information from another guest on the target system.
a flaw when clearing grant status bits prematurely. As a result, a guest system may modify or reuse a grant that is still in use by another domain. A local attacker on a guest system may modify or reuse a grant that is still in use by another domain and obtain potentially sensitive information from another guest on the target system.
The weakness exists due to flaws when clearing grant status bits. A local attacker on a guest system may modify or reuse a grant that is still in use by another domain and obtain potentially sensitive information from another guest on the target system.
a flaw when clearing grant status bits prematurely. As a result, a guest system may modify or reuse a grant that is still in use by another domain. A local attacker on a guest system may modify or reuse a grant that is still in use by another domain and obtain potentially sensitive information from another guest on the target system.
Affected software
Xen
xen (Alpine package)
xen (Alpine package)
How to mitigate CVE-2017-12855
Install update from vendor's website.
xen (Alpine package) - update to 4.6.6-r0