CVE-2017-17045: Xen
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) Physical-to-Machine (P2M) errors.
Affected products
- Xen Xen: up to and including 4.9.1
Published 2017-11-28. Last modified 2026-06-17.