#CitrixHypervisor

Новини Українськоюrss_ukr_news
2024-04-25

Чим замінити продукти VMware, які тепер дорожче: 5 альтернатив для вашої IT-інфраструктури itc.ua/ua/articles/chym-zaminy -Networks -V

🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2023-10-12

"🚨 #CitrixHypervisor Security Alert! 🚨"

Citrix has identified several security issues in Citrix Hypervisor 8.2 CU1 LTSR that could potentially compromise system security. These issues include AMD-based host compromise through a PCI device (CVE-2023-34326), host compromise with specific administrative actions (CVE-2022-1304), host crashes or unresponsiveness (CVE-2023-34324), and crashing of other VMs on AMD-based hosts (CVE-2023-34327). Additionally, a security problem affecting certain AMD CPUs, which may allow code in a guest VM to access previous integer divides in code running on the same CPU core, has been disclosed as CVE-2023-20588.

Mitigating factors include the dependency on AMD CPUs and the use of specific features. Customers not using AMD CPUs or PCI passthrough features may not be affected by some of these issues.

Citrix has released multiple security updates for Citrix Hypervisor 8.2 CU1 LTSR. Several vulnerabilities have been discovered:

  1. CVE-2023-34326: A threat that allows malicious privileged code in a guest VM to compromise an AMD-based host via a passed-through PCI device.
  2. CVE-2022-1304: A vulnerability that can compromise the host when a specific administrative action is taken.
  3. CVE-2023-34324: A flaw that can cause the host to crash or become unresponsive.
  4. CVE-2023-34327: A vulnerability that can cause a different VM running on the AMD-based host to crash.
  5. CVE-2023-20588: A security issue affecting certain AMD CPUs, allowing code in a guest VM to determine values from previous integer divides in code running on the same CPU core.

Citrix has provided hotfixes for these vulnerabilities. Affected users are advised to install these updates and follow the provided instructions. For more details, check the official Citrix article here.

Tags: #Cybersecurity #Citrix #Hypervisor #Vulnerability #AMD #CVE2023 #CVE2022 #SecurityUpdates 🛡️🔧

heise online (inoffiziell)heiseonline@squeet.me
2021-04-01
Abgesicherte Versionen von Citrix Hypervisor verhindern Zugriffe auf Host-Systeme.
DoS-Lücke in Virtualisierungsplattform Citrix Hypervisor geschlossen
heise online (inoffiziell)heiseonline@squeet.me
2020-12-21
Wichtige Sicherheitsupdates schließen Lücken in Citrix Hypervisor. Das Risiko gilt als hoch.
Citrix Hypervisor und XenServer: Ausbrüche aus virtuellen Maschinen möglich

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst