PT-2020-7238 · Citrix · Citrix Xenserver

Published

2020-01-23

·

Updated

2020-02-03

·

CVE-2012-4606

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Citrix XenServer versions 4.1, 5.0, 5.0 Update 3, 5.5, 5.6, 5.6 Common Criteria, 5.6 Feature Pack 1, 5.6 SP2, 6.0
Description The issue allows local users with access to a guest operating system to gain elevated privileges due to a Local Privilege Escalation.
Recommendations For Citrix XenServer version 4.1, update to a newer version to mitigate the risk. For Citrix XenServer version 5.0, update to a newer version to mitigate the risk. For Citrix XenServer version 5.0 Update 3, update to a newer version to mitigate the risk. For Citrix XenServer version 5.5, update to a newer version to mitigate the risk. For Citrix XenServer version 5.6, update to a newer version to mitigate the risk. For Citrix XenServer version 5.6 Common Criteria, update to a newer version to mitigate the risk. For Citrix XenServer version 5.6 Feature Pack 1, update to a newer version to mitigate the risk. For Citrix XenServer version 5.6 SP2, update to a newer version to mitigate the risk. For Citrix XenServer version 6.0, update to a newer version to mitigate the risk.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4606

Affected Products

Citrix Xenserver