Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2019.4056 Hypervisor Security Update 1 November 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Citrix Hypervisor Publisher: Citrix Operating System: Citrix XenServer Impact/Access: Increased Privileges -- Existing Account Denial of Service -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2019-18425 CVE-2019-18424 CVE-2019-18421 CVE-2019-18420 Original Bulletin: https://support.citrix.com/article/CTX263477 - --------------------------BEGIN INCLUDED TEXT-------------------- Hypervisor Security Update Reference: CTX263477 Category : High Created : 31 Oct 2019 Modified : 31 Oct 2019 Applicable Products o Citrix Hypervisor 8.0 o XenServer 7.6 o XenServer 7.1 LTSR Cumulative Update 2 o XenServer 7.0 Description of Problem A number of vulnerabilities have been found in Citrix Hypervisor (formerly Citrix XenServer) that allow the host to be compromised by: i. Privileged code in a guest VM that has been assigned a PCI passthrough device ii. Privileged code in a PV guest VM iii. Unprivileged code in a 32-bit PV guest VM These vulnerabilities have the following identifiers: o CVE-2019-18420 o CVE-2019-18421 o CVE-2019-18424 o CVE-2019-18425 These issues affect all currently supported versions of Citrix Hypervisor up to and including Citrix Hypervisor 8.0. Mitigating Factors Customers running only HVM workloads and not making use of PCI passthrough functionality are not affected by these issues. Note that all Microsoft Windows VMs run as HVM VMs. What Customers Should Do Hotfixes have been released to address these issues. Citrix recommends that affected customers install these hotfixes as their patching schedules allow. The hotfixes can be downloaded from the following locations: Citrix Hypervisor 8.0: CTX262555 - https://support.citrix.com/article/CTX262555 CTX258428 - https://support.citrix.com/article/CTX258428 Citrix XenServer 7.6: CTX262554 - https://support.citrix.com/article/CTX262554 CTX258425 - https://support.citrix.com/article/CTX258425 Citrix XenServer 7.1 LTSR CU2: CTX262553 - https://support.citrix.com/article/CTX262553 CTX258424 - https://support.citrix.com/article/CTX258424 Citrix XenServer 7.0: CTX258417 - https://support.citrix.com/article/CTX258417 CTX258423 - https://support.citrix.com/article/CTX258423 Changelog +------------------------------------+----------------------------------------+ |Date |Change | +------------------------------------+----------------------------------------+ |31st October 2019 |Initial publication | +------------------------------------+----------------------------------------+ - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXbtz5maOgq3Tt24GAQimFxAA2CLqTRaDJbnAr2sWvu8AgPwxDI25jOYV 7Ls8fN1XEAlpJMbhI9LC2hO/PwA7Ow1KtRzRFiGG9GL+TCuQK/48WzJKRHyEVHBG 35c5NdoTybH6rDNPnsWhYHVE/L/XKnaZwWliNtrEbI0JNBCZxs7zWHWQp8zLJUYI x/0Iz7AgSBIuRTdezsBai6pWD+rQR6Fhu7KrF1tSxQDq/u4NsY5LhWnOUa7E2MYw dJDkYPQeqpdlKWAcWjNCmFYg8UaJvClZAm5cDxUuAfXMz37Th+NOm67TJcHzHxr2 HLzbFbF7oKXZwPhLzlpAFnOwEu8nKRIDMgvanhX77VzuQDa+mxiMXMLYuKF0XEcv y+x9Sv4EeTtud/fz8wtPEfvcth6tn3n5FKZJctTxTJdvZeQRWG8Nl832mih9mXx6 JqCGPHrdSbGYchP89aOHqCjBR0ZEVqlBKoQRgCyjTIGhm0hCXRiexCPvMn+xBTDI jWY2A88rDuZ1jpwNBHRqSOXtmSo1aq2CAeCt2NwjJjatHvcBBSVm6UhXtvTWdSb7 cvRVhrd5yYJMR/6VX8vO3I7EVceARIUN73gcEmisrm5Rkx2FbtLwHpmMlX7yoPpd ICJIBMHEsU1s+JgUz5lTCYQKIPBEWDJRb2Aw9oXehEBcBJFdXpWvpbBGX072rzCk CIrDQrcUsDs= =tWi2 -----END PGP SIGNATURE-----