Xen CVE-2017-17045 Privilege Escalation Vulnerability
BID:102013
Info
Xen CVE-2017-17045 Privilege Escalation Vulnerability
| Bugtraq ID: | 102013 |
| Class: | Design Error |
| CVE: |
CVE-2017-17045 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2017 12:00AM |
| Updated: | Apr 15 2019 05:00PM |
| Credit: | George Dunlap of Citrix. |
| Vulnerable: |
Xen Xen 4.9 Xen Xen 4.8 Xen Xen 4.7 Xen Xen 4.6 Xen Xen 4.0.4 Xen Xen 4.0.1 Xen Xen 4.6.3 Xen Xen 4.5.3 Xen Xen 4.5.0 Xen Xen 4.4.1 Xen Xen 4.4.0 Xen Xen 4.3.1 Xen Xen 4.3.0 Xen Xen 4.2.3 Xen Xen 4.2.2 Xen Xen 4.2.1 Xen Xen 4.2.0 Xen Xen 4.1.5 Xen Xen 4.1.3 Xen Xen 4.1.2 Xen Xen 4.1.0 Xen Xen 4.0 Xen Xen 3.4.4 Xen Xen 3.4.3 Xen Xen 3.4.2 Xen Xen 3.4.1 Citrix XenServer 6.0.2 Citrix XenServer 7.2 Citrix XenServer 7.1 LTSR CU1 Citrix XenServer 7.1 Citrix XenServer 7.0 Citrix XenServer 6.5 Citrix XenServer 6.2 |
| Not Vulnerable: |
Citrix XenServer 6.0.2 Common Criteria Citrix XenServer 6.5 Service Pack 1 Citrix XenServer 6.2 Service Pack 1 |
Discussion
Xen CVE-2017-17045 Privilege Escalation Vulnerability
Xen is prone to a privilege-escalation vulnerability.
An attacker can exploit this issue to obtain sensitive information or to gain elevated privileges. Failed exploit attempts will likely cause a denial-of-service condition.
Xen is prone to a privilege-escalation vulnerability.
An attacker can exploit this issue to obtain sensitive information or to gain elevated privileges. Failed exploit attempts will likely cause a denial-of-service condition.
Exploit / POC
Xen CVE-2017-17045 Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen CVE-2017-17045 Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Xen CVE-2017-17045 Privilege Escalation Vulnerability
References:
References:
- Bug 1513336 - (CVE-2017-17045, xsa247) CVE-2017-17045 xsa247 xen: Missing p2m er (Red Hat)
- CVE-2017-17045 (Red Hat)
- Xen Homepage (XenSource )
- XSA-247: Missing p2m error checking in PoD code (Xen)
- Citrix XenServer Multiple Security Updates (Citrix)