Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2012-5525 — XEN vulnerability
7 documents6 sources
Severity
4.7MEDIUMNVD
EPSS
6.9%
top 8.59%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedDec 13
Latest updateMay 17
Description
The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read.
CVSS vector
AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9