Impact
VM administrators are able to set the VM.other‑config:is_system_domain flag, a setting that should be restricted to higher‑privilege pool administrators. When a VM is marked as a system domain it can be hidden from management tools and ignored during certain host or pool operations, providing a stealthy foothold for the attacker. This flaw effectively grants a lower‑privilege administrator the ability to alter system‑critical configurations, potentially leading to denial against the host if the marked VM interferes with normal operation. The weakness constitutes a CWE‑250 "Privilege‑Controlled Missing or Incorrect Authorization" vulnerability.
Affected Systems
The vulnerability affects Xen XAPI, the role‑based access control component of Xen Server. Users with the vm‑admin role on any Xen Server deployment can exploit the flaw, regardless of the specific Xen version, as the product documentation does not state any version restrictions. No specific version information is provided in the CNA data, so all XAPI installations that include the exposed API call are potentially impacted.
Risk and Exploitability
With a CVSS score of 9.4 the flaw is considered critical, and the EPSS score of < 1 % indicates a low but non‑zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, and the as a vm-admin. An attacker with marking VMs as system domains, thereby bypassing intended administrative boundaries and potentially disrupting host or pool operations.
OpenCVE Enrichment