Executive brief
The Xen Project Windows Paravirtual (PV) drivers, which improve performance for Windows virtual machines running on Xen, contain a security flaw in how they manage access permissions. Because certain driver components lack proper security restrictions, any standard user on the virtual machine can interact with them directly. This allows a low-privileged user to gain full control over the guest operating system, potentially leading to data theft or complete system compromise.
Technical details
The Windows PV drivers (specifically XenCons, XenIface, and XenBus) expose device objects to userspace without associated security descriptors. This lack of access control (CWE-276) means these facilities are fully accessible to unprivileged users. An attacker with local access to a Windows guest VM can exploit these unprotected interfaces to escalate their privileges to the level of the guest kernel. The vulnerability in XenCons (CVE-2025-27462) was introduced in version 9.0.0, while XenIface and XenBus have been vulnerable since their inception. Patches and a mitigation PowerShell script are available from the Xen Project.
Affected products
- Xen Project Windows PV drivers All versions (XenCons since 9.0.0)
Timeline
- 2025-05-27: advisory: Initial public release of XSA-468
- 2026-07-09: disclosed: CVE-2025-27462 published to NVD