PT-2007-6103 · Xen+1 · Xen+1

Joris Van Rantwijk

·

Published

2007-09-27

·

Updated

2018-10-15

·

CVE-2007-4993

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Xen version 3.0.3
Description The issue allows local users with elevated privileges in a guest domain to execute arbitrary commands in domain 0. This is achieved by creating a crafted grub.conf file, whose contents are then used in exec statements, potentially leading to unauthorized command execution.
Recommendations For Xen version 3.0.3, consider restricting access to the grub.conf file to prevent local users from crafting malicious configurations until a patch is available. As a temporary workaround, monitor domain 0 for suspicious activity and limit the privileges of guest domain users to minimize potential damage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4993
DSA-1384-1
RHSA-2007:0323
RHSA-2007_0323

Affected Products

Red Hat
Xen