Denial of Service Vulnerability in Citrix XenServer and Xen Hypervisors
CVE-2012-3494
Currently unrated
What is CVE-2012-3494?
The vulnerability allows local OS guest users on x86-64 systems to exploit the set_debugreg hypercall in Xen and Citrix XenServer platforms. By writing to reserved bits of the DR7 debug control register, an attacker can trigger a denial of service, leading to a host crash. This serious flaw compromises system stability and may provide a gateway for further attacks, emphasizing the need for immediate mitigation.
References
Timeline
Vulnerability published
Vulnerability Reserved