CVE-2017-15597 is a critical memory corruption vulnerability affecting Xen through version 4.9.x, stemming from incorrect assumptions in grant copying code. A malicious guest administrator can exploit this flaw to cause hypervisor memory corruption, leading to a host crash and Denial of Service, with potential for privilege escalation and information leaks. With a CVSS score of 9.1 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity, requiring high privileges. While there are no known public exploits or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.9.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:rc7:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.