cbcvebase.
CVE-2014-7188
published 2014-10-02

CVE-2014-7188: The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM…

PriorityP428high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
0.86%
54.4th percentile
The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.4.1-3 (bookworm)xen 4.4.1-3 (bookworm)
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen>= 0 < 4.4.1-34.4.1-3
xenxen>= 0 < 4.4.1-34.4.1-3
xenxen>= 0 < 4.4.1-34.4.1-3
xenxen>= 0 < 4.4.1-34.4.1-3

CVSS provenance

nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
osv8.3HIGH
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.