CVE-2012-4606: Citrix Xenserver

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.

Affected products

  • Citrix Xenserver: version 4.1 only; version 5.0 only; version 5.5 only; version 5.6 only; version 6.0 only

Published 2020-01-23. Last modified 2026-06-16.