CVE-2017-8903: High severity xen xapi vulnerability
Published May 11, 2017
·Updated
Xen through 4.8.x on 64-bit platforms mishandles page tables after an IRET hypercall, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-213.
Affected Software
2 affected components
Xen XAPI=4.8.0
Xen XAPI=4.8.1
Remediation
Patch Available
Event History
May 11, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8903?
CVE-2017-8903 is considered a high severity vulnerability as it allows potential arbitrary code execution on the host OS.
2
How do I fix CVE-2017-8903?
To mitigate CVE-2017-8903, you should upgrade to a patched version of Xen that addresses this vulnerability.
3
Who is affected by CVE-2017-8903?
CVE-2017-8903 affects Xen versions 4.8.0 and 4.8.1 on 64-bit platforms.
4
What type of vulnerability is CVE-2017-8903?
CVE-2017-8903 is a privilege escalation vulnerability that impacts PV guest OS users.
5
What exploitation risks are associated with CVE-2017-8903?
Exploitation of CVE-2017-8903 could allow an attacker to execute arbitrary code on the host operating system.