OSVDB ID: 85199

Title: Xen Transcendent Memory (TMEM) Hypercall Multiple Sub-operation Validation Weakness Local Privilege Escalation

Info

Disclosure

Sep 05, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Sep 05, 2012

Description

Xen contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when multiple sub-operations in the transcendent memory (TMEM) hypercall fails to properly verify input or guest permissions. This may allow a local attacker to gain escalated privileges.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Workaround
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Authentication Required

Solution

Currently, there are no known upgrades or patches to correct this vulnerability. It is possible to temporarily work around the flaw by implementing the following workaround: Disable TMEM.

Products

Citrix Systems, Inc.

Xen

4.0
4.2
4.1

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/85199