CVE-2013-4554: Xen
Medium severity, CVSS 5.2. EPSS: 0.6% chance of exploitation in the next 30 days.
Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2.
Affected products
- Xen Xen: version 3.0.3 only; version 3.0.4 only; version 3.1.3 only; version 3.1.4 only; version 3.2.0 only; version 3.2.1 only; …
Published 2013-12-24. Last modified 2026-06-16.