CVE-2016-9637
Description
The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.
Risk Information
Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.087
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in Citrix XenCenter 6.0.2 | Windows |
| Multiple Vulnerabilities are affected in Citrix XenCenter 6.2.0 | Windows |
| Multiple Vulnerabilities are affected in Citrix XenCenter 6.5 | Windows |
| Multiple Vulnerabilities are affected in Citrix XenCenter 7.0 | Windows |
| (RHSA-2016:2963) Important: xen security update xen-3.0.3-148.el5_11.i386.rpm | Linux |
| (RHSA-2016:2963) Important: xen security update xen-3.0.3-148.el5_11.x86_64.rpm | Linux |
| (RHSA-2016:2963) Important: xen security update xen-devel-3.0.3-148.el5_11.i386.rpm | Linux |
| (RHSA-2016:2963) Important: xen security update xen-devel-3.0.3-148.el5_11.x86_64.rpm | Linux |
| (RHSA-2016:2963) Important: xen security update xen-libs-3.0.3-148.el5_11.i386.rpm | Linux |
| (RHSA-2016:2963) Important: xen security update xen-libs-3.0.3-148.el5_11.x86_64.rpm | Linux |
| CVE-2016-9637 | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234