PT-2020-7238 · Citrix · Citrix Xenserver
Published
2020-01-23
·
Updated
2020-02-03
·
CVE-2012-4606
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Citrix XenServer versions 4.1, 5.0, 5.0 Update 3, 5.5, 5.6, 5.6 Common Criteria, 5.6 Feature Pack 1, 5.6 SP2, 6.0
Description
The issue allows local users with access to a guest operating system to gain elevated privileges due to a Local Privilege Escalation.
Recommendations
For Citrix XenServer version 4.1, update to a newer version to mitigate the risk.
For Citrix XenServer version 5.0, update to a newer version to mitigate the risk.
For Citrix XenServer version 5.0 Update 3, update to a newer version to mitigate the risk.
For Citrix XenServer version 5.5, update to a newer version to mitigate the risk.
For Citrix XenServer version 5.6, update to a newer version to mitigate the risk.
For Citrix XenServer version 5.6 Common Criteria, update to a newer version to mitigate the risk.
For Citrix XenServer version 5.6 Feature Pack 1, update to a newer version to mitigate the risk.
For Citrix XenServer version 5.6 SP2, update to a newer version to mitigate the risk.
For Citrix XenServer version 6.0, update to a newer version to mitigate the risk.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citrix Xenserver