6.9
CVSSv2

CVE-2007-4993

Published: 27/09/2007 Updated: 15/10/2018
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in domain 0 via a crafted grub.conf file whose contents are used in exec statements.

Vulnerable Product Search on Vulmon Subscribe to Product

xensource inc xen 3.0.3

Vendor Advisories

Joris van Rantwijk discovered that the Xen host did not correctly validate the contents of a Xen guests’s grugconf file Xen guest root users could exploit this to run arbitrary commands on the host when the guest system was rebooted ...

Exploits

source: wwwsecurityfocuscom/bid/25825/info Xen is prone to a local command-injection vulnerability that can lead to privilege escalation This issue occurs because the application fails to validate input in the 'tools/pygrub/src/GrubConfpy' script This vulnerability affects Xen 303; other versions may be affected as well An attac ...