Denial of Service Vulnerability in Citrix XenServer and Xen Hypervisors
CVE-2012-3494

Currently unrated

Key Information:

Vendor
CVE Published:
23 November 2012

What is CVE-2012-3494?

The vulnerability allows local OS guest users on x86-64 systems to exploit the set_debugreg hypercall in Xen and Citrix XenServer platforms. By writing to reserved bits of the DR7 debug control register, an attacker can trigger a denial of service, leading to a host crash. This serious flaw compromises system stability and may provide a gateway for further attacks, emphasizing the need for immediate mitigation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.