Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Xenserver | Citrix | 4.1 (including) | 4.1 (including) |
| Xenserver | Citrix | 5.0 (including) | 5.0 (including) |
| Xenserver | Citrix | 5.0-update_3 (including) | 5.0-update_3 (including) |
| Xenserver | Citrix | 5.5 (including) | 5.5 (including) |
| Xenserver | Citrix | 5.6 (including) | 5.6 (including) |
| Xenserver | Citrix | 5.6-common_criteria (including) | 5.6-common_criteria (including) |
| Xenserver | Citrix | 5.6-fp1 (including) | 5.6-fp1 (including) |
| Xenserver | Citrix | 5.6-sp2 (including) | 5.6-sp2 (including) |
| Xenserver | Citrix | 6.0 (including) | 6.0 (including) |