NVD

Id
86123  
Name
CVE-2017-8904  
Description
Xen through 4.8.x mishandles the contains segment descriptors property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.  
Reject
 
CVSS Version
2  
CVSS Score
6.8  
Severity
Medium  
CVSS Base Score
6.8  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
3.1  
CVSS Vector
(AV:L/AC:L/Au:S/C:C/I:C/A:C)  
Pub Date
2017-07-18  
Published
2017-05-11  
Modified Date
2017-07-10  
Seq
2017-8904  

Actions