ZeroHour

CVE-2016-9386

CVSS 3.0
7.8 high
EPSS
<1%p38
Published
()
Modified
Description

The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.

Vendors
citrixxen
Products
xenserver, xen
Weakness
CWE-264
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.