Executive brief
The Xen Project Windows Paravirtual (PV) drivers, which improve the performance of Windows virtual machines running on Xen, contain a security flaw in the XenBus component. This flaw allows standard, unprivileged users on a Windows virtual machine to gain full administrative or kernel-level control of that system. This could lead to a complete compromise of the virtual machine's data and operations.
Technical details
The XenBus driver in the Xen Project Windows PV driver suite fails to apply security descriptors to various facilities exposed to userspace. This lack of access control (CWE-276) means these interfaces are fully accessible to unprivileged local users. An attacker with local access to a Windows guest VM can exploit these unprotected interfaces to achieve a privilege escalation from a standard user to the guest kernel. The vulnerability affects all versions of the XenBus driver. Patches have been released by the Xen Project to apply the necessary security descriptors.
Affected products
- Xen Project Windows PV drivers All versions
Timeline
- 2025-05-27: disclosed: Initial public release of XSA-468
- 2025-05-27: patched: Patches released for XenBus, XenCons, and XenIface
- 2026-07-09: advisory: NVD publication date