CVE-2016-9637

Description

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.087

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Citrix XenCenter 6.0.2Windows
Multiple Vulnerabilities are affected in Citrix XenCenter 6.2.0Windows
Multiple Vulnerabilities are affected in Citrix XenCenter 6.5Windows
Multiple Vulnerabilities are affected in Citrix XenCenter 7.0Windows
(RHSA-2016:2963) Important: xen security update xen-3.0.3-148.el5_11.i386.rpmLinux
(RHSA-2016:2963) Important: xen security update xen-3.0.3-148.el5_11.x86_64.rpmLinux
(RHSA-2016:2963) Important: xen security update xen-devel-3.0.3-148.el5_11.i386.rpmLinux
(RHSA-2016:2963) Important: xen security update xen-devel-3.0.3-148.el5_11.x86_64.rpmLinux
(RHSA-2016:2963) Important: xen security update xen-libs-3.0.3-148.el5_11.i386.rpmLinux
(RHSA-2016:2963) Important: xen security update xen-libs-3.0.3-148.el5_11.x86_64.rpmLinux
CVE-2016-9637NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234