Impact
The Xen Windows PV driver set contains a XenIface device that is exposed to userspace without a defined security descriptor. Because the device lacks permission checks, any local user running inside the Windows virtual machine can read from and write to the XenIface endpoint. This flaw is identified as CWE‑276 (Incorrect Permissions) and effectively allows an attacker to gain elevated privileges within the guest operating system.
Affected Systems
The vulnerability impacts Xen Windows PV drivers, specifically the XenIface device used in Windows virtual machines. No particular version numbers are identified in the CNA information, so all current releases of the Xen Windows PV driver are potentially affected.
Risk and Exploitability
The CVSS score of 9.4 classifies this issue as critical, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is local to the virtual machine; any user with local access to the guest can exploit the missing security descriptor to elevate privileges.
OpenCVE Enrichment