First published: Wed Jul 05 2017(Updated: )
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen XAPI | <=4.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10915 is considered a high severity vulnerability due to its potential to allow unauthorized access to Xen privileges.
CVE-2017-10915 allows guest OS users to escalate their privileges, which can compromise the security of the entire virtualization host.
To fix CVE-2017-10915, users should upgrade to Xen version 4.8.2 or later.
CVE-2017-10915 affects Xen versions up to and including 4.8.1.
The attack vector for CVE-2017-10915 involves exploiting a race condition in the shadow-paging feature of Xen.