CVE-2013-4554: Medium severity xen xapi vulnerability
Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4554?
CVE-2013-4554 is considered a high severity vulnerability as it allows local guest users to escalate privileges.
How do I fix CVE-2013-4554?
To fix CVE-2013-4554, update your Xen hypervisor to a version that has addressed this vulnerability according to vendor release notes.
Which versions of Xen are affected by CVE-2013-4554?
CVE-2013-4554 affects Xen versions 3.0.3 through 4.1.x, 4.2.x, and 4.3.x specifically.
What types of attacks can be executed due to CVE-2013-4554?
Due to CVE-2013-4554, local guest users can exploit the vulnerability to gain unauthorized access to hypercalls.
Is CVE-2013-4554 a remote or local vulnerability?
CVE-2013-4554 is a local vulnerability, as it requires an attacker to have access to a guest user environment.