CVE-2017-7228, also known as XSA-212, is a high-severity vulnerability affecting Xen versions 4.4.x through 4.8.x. It stems from an insufficient input validation in the XENMEM_exchange function, allowing a privileged guest to perform out-of-bounds memory accesses within the hypervisor. With a CVSS score of 8.2 (High), this vulnerability presents a local attack vector with low complexity, enabling a high-privileged attacker to achieve complete compromise of confidentiality, integrity, and availability of the host system. While not listed on the KEV catalog or Hot List, and showing no active exploitation or significant community discussion, a public exploit (EDB-41870) demonstrating a PV guest breakout is available, indicating its exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:xen:xen:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.