Skip to main content

Citrix Releases Security Update for Hypervisor

Security update addresses four vulnerabilities affecting Citrix Hypervisor

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security update addresses four vulnerabilities affecting Citrix Hypervisor


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Citrix has released a security update to address four vulnerabilities affecting Citrix Hypervisor. The vulnerabilities CVE-2022-42316, CVE-2022-42317, and CVE-2022-42318 may allow a privileged user in a guest VM to cause part of the management service to become unresponsive, resulting in the inability to create new guests or modify the configuration of running guests. CVE-2022-42323 is related to a vulnerability in Xen.

An attacker could exploit some of these vulnerabilities to carry out a denial-of-service (DoS) attack.


Remediation advice

Affected organisations are encouraged to review Citrix Security Bulletin CTX472925 and apply the relevant updates.


Remediation steps


CVE Vulnerabilities

Last edited: 3 November 2022 2:12 pm