CVE-2018-10472
Last modified
CVE-2018-10472 is a vulnerability of currently unknown severity. An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | <= 4.10.1 |
| Debian | Debian Linux | 9.0 |
References
- http://www.securityfocus.com/bid/104002Third Party Advisory, VDB Entry
- https://www.debian.org/security/2018/dsa-4201Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-258.htmlMitigation, Vendor Advisory
- http://www.securityfocus.com/bid/104002Third Party Advisory, VDB Entry
- https://www.debian.org/security/2018/dsa-4201Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-258.htmlMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10472?
How severe is CVE-2018-10472?
How do I fix CVE-2018-10472?
Are you affected by CVE-2018-10472?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
