CVE-2016-5302: Critical severity xenserver vulnerability
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5302?
CVE-2016-5302 has a high severity level due to its potential for remote exploitation on the management network.
How do I fix CVE-2016-5302?
To fix CVE-2016-5302, apply Hotfix XS70E003 or later for Citrix XenServer 7.0.
Who is affected by CVE-2016-5302?
CVE-2016-5302 affects Citrix XenServer versions prior to Hotfix XS70E003 deployed in environments upgraded from earlier releases.
What are the potential impacts of CVE-2016-5302?
The potential impacts of CVE-2016-5302 include unauthorized access to the host by exploiting Active Directory credentials.
Can CVE-2016-5302 be exploited remotely?
Yes, CVE-2016-5302 can be exploited remotely by attackers on the management network.