CVE-2018-7541 is a high-severity vulnerability affecting Xen through version 4.10.x, including Debian distributions. It allows a guest OS user to trigger a hypervisor crash (Denial of Service) or escalate privileges by manipulating grant-table transitions from v2 to v1. With a CVSS score of 8.8, this vulnerability is easily exploitable locally with low privileges, leading to high impact on confidentiality, integrity, and availability. Currently, there is no public exploit code available, nor is it listed on the KEV catalog, indicating no active exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.10.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.