SB2023010302 - Security restrictions bypass in Xen APIC accesses feature



SB2023010302 - Security restrictions bypass in Xen APIC accesses feature

Published: January 3, 2023

Security Bulletin ID SB2023010302
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Privilege Management (CVE-ID: CVE-2022-42327)

The vulnerability allows a malicious guest to escalate privileges on the system.

The vulnerability exists due to improper privilege management. A malicious guest is able to access unintended shared memory page, read and write the global shared xAPIC page by moving the local APIC out of xAPIC mode.


Remediation

Install update from vendor's website.