#VU17905 Improper access control in Xen - CVE-2019-17342
Published: March 6, 2019 / Updated: July 28, 2020
Xen
Xen Project
Description
The vulnerability exists due security violations within the page structure access control implementation with introduction of XENMEM_exchange hypercall. A local user can leak arbitrary amounts of memory or use a cooperating pair of PV and HVM/PVH guests to get a writable pagetable entry and escalate privileges on the host operating system.