Xen 'grant_table.c' Privilege Escalation Vulnerability
BID:100817
CVE-2017-14318 |Info
Xen 'grant_table.c' Privilege Escalation Vulnerability
| Bugtraq ID: | 100817 |
| Class: | Design Error |
| CVE: |
CVE-2017-14318 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2017 12:00AM |
| Updated: | Sep 12 2017 12:00AM |
| Credit: | Matthew Daley |
| Vulnerable: |
Xen Xen 4.9 Xen Xen 4.5.3 Xen Xen 4.5.0 Redhat Enterprise Linux 5 |
| Not Vulnerable: | |
Discussion
Xen 'grant_table.c' Privilege Escalation Vulnerability
Xen is prone to a privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges. Failed exploit attempts will likely result in denial of service conditions.
Xen 4.5.x through 4.9.x are vulnerable; other versions may also be affected.
Xen is prone to a privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges. Failed exploit attempts will likely result in denial of service conditions.
Xen 4.5.x through 4.9.x are vulnerable; other versions may also be affected.
Exploit / POC
Xen 'grant_table.c' Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen 'grant_table.c' Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Xen 'grant_table.c' Privilege Escalation Vulnerability
References:
References:
- CVE-2017-14318 (Redhat)
- Xen Homepage (XenSource )
- Bug 1486708 - (CVE-2017-14318, xsa232) CVE-2017-14318 xsa232 xen: Missing check (Redhat)
- Xen Security Advisory CVE-2017-14318 / XSA-232 (Xen)