#VU12543 Information disclosure in Xen - CVE-2018-10472
Published: May 9, 2018 / Updated: May 10, 2018
Xen
Xen Project
Description
The vulnerability allows an adjacent attacker to obtain potentially sensitive information on the target system.
The weakness exists in certain configurations due to improper information control. An adjacent attacker can read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.