Citrix Releases Security Update for Hypervisor
Security update addresses four vulnerabilities affecting Citrix Hypervisor
Summary
Security update addresses four vulnerabilities affecting Citrix Hypervisor
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Citrix has released a security update to address four vulnerabilities affecting Citrix Hypervisor. The vulnerabilities CVE-2022-42316, CVE-2022-42317, and CVE-2022-42318 may allow a privileged user in a guest VM to cause part of the management service to become unresponsive, resulting in the inability to create new guests or modify the configuration of running guests. CVE-2022-42323 is related to a vulnerability in Xen.
An attacker could exploit some of these vulnerabilities to carry out a denial-of-service (DoS) attack.
Remediation advice
Affected organisations are encouraged to review Citrix Security Bulletin CTX472925 and apply the relevant updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Citrix Hypervisor | Hotfix XS82ECU1020 https://support.citrix.com/article/CTX472925/hotfix-xs82ecu1020-for-citrix-hypervisor-82-cumulative-update-1 |
CVE Vulnerabilities
Last edited: 3 November 2022 2:12 pm