Citrix Releases Security Update for Hypervisor
Security update addresses two vulnerabilities affecting Citrix Hypervisor
Summary
Security update addresses two vulnerabilities affecting Citrix Hypervisor
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Citrix has released a security update to address two vulnerabilities affecting Citrix Hypervisor. The vulnerability known as CVE-2022-33748 could allow two malicious privileged users in separate guest VMs to cause the host to crash or become unresponsive. CVE-2022-33749 could allow a malicious unauthenticated user on the management network to cause the management service on the host to crash or become unresponsive.
An attacker could exploit these vulnerabilities to carry out a denial-of-service (DoS) attack.
Remediation advice
Affected organisations are encouraged to review Citrix Security Update CTX465146 and apply the relevant updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Citrix Hypervisor | Hotfix XS82ECU1016 https://support.citrix.com/article/CTX465169/hotfix-xs82ecu1016-for-citrix-hypervisor-82-cumulative-update-1 |
| Patch |
Citrix Hypervisor | Hotfix XS82ECU1019 https://support.citrix.com/article/CTX466065/hotfix-xs82ecu1019-for-citrix-hypervisor-82-cumulative-update-1 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 12 October 2022 4:30 pm