Xapi Vulnerability in Citrix Hypervisor Allowing Malicious Metadata Backup Manipulation
CVE-2024-31144
What is CVE-2024-31144?
The Xapi component in Citrix Hypervisor allows for backup and restoration of metadata related to Virtual Machines (VMs) and Storage Repositories (SRs). The metadata is stored in a Virtual Disk Image (VDI) and is critical for recovery scenarios. A malicious guest could exploit this functionality by manipulating its disk to imitate a legitimate metadata backup. Given that the restoration process involves searching VDIs in UUID order to locate the required metadata, a guest with one disk has an increased probability of being erroneously identified as the metadata VDI. This aspect could be exploited, leading to unauthorized access or manipulation of critical metadata.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Xen consult Xen advisory XSA-459
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
