1.9
CVSSv2

CVE-2014-8595

Published: 19/11/2014 Updated: 30/10/2018
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 up to and including 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 7.0

xen xen 3.3.1

xen xen 3.3.2

xen xen 4.0.2

xen xen 4.0.3

xen xen 4.1.5

xen xen 4.1.6.1

xen xen 4.4.0

xen xen 3.4.0

xen xen 3.4.1

xen xen 3.4.2

xen xen 4.0.4

xen xen 4.1.0

xen xen 4.2.0

xen xen 4.2.1

xen xen 3.2.3

xen xen 3.3.0

xen xen 4.0.0

xen xen 4.0.1

xen xen 4.1.3

xen xen 4.1.4

xen xen 4.3.0

xen xen 4.3.1

xen xen 3.2.1

xen xen 3.2.2

xen xen 3.4.3

xen xen 3.4.4

xen xen 4.1.1

xen xen 4.1.2

xen xen 4.2.2

xen xen 4.2.3

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Debian Bug report logs - #770230 xen: CVE-2014-5146 CVE-2014-5149 CVE-2014-8594 CVE-2014-8595 CVE-2014-9030 Package: src:xen; Maintainer for src:xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 19 Nov 2014 22:48:01 UTC Severity: important Tags ...
Multiple security issues have been discovered in the Xen virtualisation solution which may result in denial of service, information disclosure or privilege escalation CVE-2014-8594 Roger Pau Monne and Jan Beulich discovered that incomplete restrictions on MMU update hypercalls may result in privilege escalation CVE-2014-8595 Jan ...
arch/x86/x86_emulate/x86_emulatec in Xen 321 through 44x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction ...