CVE-2014-8595 — Missing Authorization in XEN
Severity
1.9LOWNVD
EPSS
0.1%
top 78.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 19
Latest updateMay 14
Description
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.
CVSS vector
AV:L/AC:M/C:N/I:N/A:PExploitability: 3.4 | Impact: 2.9
Affected Packages4 packages
Also affects: Debian Linux 7.0