XenServer and Citrix Hypervisor vulnerabilities

B2B Cyber ​​Security ShortNews

Share post

Citrix warns of two vulnerabilities in XenServer and Citrix Hypervisor. The security vulnerabilities are only moderately serious, but a quick update is still recommended. Citrix already provides hotfixes for this.

According to Citrix, two issues have been identified affecting XenServer and Citrix Hypervisor. A vulnerability could allow unprivileged code in a guest VM to access the memory contents of its own VM or other VMs on the same host. This can result in data or access data being stolen.

Memory contents of other VMs can be copied

Citrix is ​​reporting the issues under the following CVE identifiers: CVE-2024-2201 and CVE-2024-31142. However, CVE-2024-2201 only affects virtual machines that use Intel CPUs. On the other hand, CVE-2024-31142 only affects VMs that use AMD CPUs.

Citrix explains another vulnerability under CVE-2023-46842. It is possible for attackers to crash the host by executing malicious code with privileges in a guest VM. The problem affects VMs under Intel as well as AMD processors.

Updates are available

For users of XenServer 8, there is an update to both the Early Access and the normal update channels. Appropriate instructions are available in the white paper from Citrix for XenServer 8.

For users of An update and instructions are also available for Citrix Hypervisor 8.2 CU1 LTSR.

More at Sophos.com

 

Matching articles on the topic

XenServer and Citrix Hypervisor vulnerabilities

Citrix warns of two vulnerabilities in XenServer and Citrix Hypervisor. The security vulnerabilities are only moderately serious, but there is still one ➡ Read more

Successful phishing: Attackers attack MFA service providers for Cisco Duo 

Cisco calls its Zero Trust security platform “Duo” for short. Their access is protected by state-of-the-art multi-factor authentication (MFA). Through a ➡ Read more

North Korean state hackers are relying on new espionage tactics

First talk, then hack: The North Korean hacker group TA427 tries to address foreign policy experts in a rather unspectacular way in order to get their point of view ➡ Read more

Disinformation campaigns from China

The report that China is allegedly disrupting and manipulating elections by using AI-generated content to spread disinformation should not be ➡ Read more

OT security status report

A recent survey of industrial companies worldwide – including Germany – paints a worrying picture about the state of OT security ➡ Read more

Holy LG WebOS endangers presentation TVs in companies 

Many companies now have large TV sets in conference rooms for events or video conferences. This unexpectedly also has vulnerabilities behind it ➡ Read more

BSI warns: Palo Alto firewalls with critical vulnerability 

The BSI warns: The PAN-OS operating system has a glaring, critical vulnerability that was rated with a CVSS value of 10.0 out of 10. ➡ Read more

XZ vulnerability: free XZ backdoor scanner

Bitdefender Labs offers a free scanner that companies can use to update their IT systems, which was announced on March 29, 2024 ➡ Read more