CVE-2014-8866 — XEN vulnerability
Severity
4.7MEDIUMNVD
EPSS
0.1%
top 74.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 1
Latest updateMay 14
Description
The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving altering the high halves of registers while in 64-bit mode.
CVSS vector
AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9
Affected Packages4 packages
Also affects: Debian Linux 7.0
Patches
🔴Vulnerability Details
2📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2014-8866 xen: Excessive checking in compatibility mode hypercall argument translation (xsa111)↗2014-11-14