CVE-2016-7093: Xen
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.
Affected products
- Xen Xen: version 4.5.3 only; version 4.6.3 only; version 4.7.0 only
Published 2016-09-21. Last modified 2026-06-17.