8.2

CVE-2016-7093

Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xen ≫ Xen Version 4.5.3
Xen ≫ Xen Version 4.6.3
Xen ≫ Xen Version 4.7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.34
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.2 1.5 6
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://security.gentoo.org/glsa/201611-09
http://support.citrix.com/article/CTX216071
Third Party Advisory
http://www.securityfocus.com/bid/92865
http://www.securitytracker.com/id/1036752
Third Party Advisory
VDB Entry
http://xenbits.xen.org/xsa/advisory-186.html
Patch
Vendor Advisory
http://xenbits.xen.org/xsa/xsa186-0001-x86-emulate-Correct-boundary-interactions-of-emulate.patch
Patch
Vendor Advisory