ZeroHour

CVE-2018-10472

CVSS 3.0
5.6 medium
EPSS
<1%p30
Published
()
Modified
Description

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

Vendors
xendebian
Products
xen, debian linux
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.