VYPR
High severity7.5NVD Advisory· Published Feb 17, 2017· Updated May 13, 2026

CVE-2016-9637

CVE-2016-9637

Description

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.

Affected products

4
  • cpe:2.3:a:citrix:xenserver:6.0.2:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:citrix:xenserver:6.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:citrix:xenserver:6.2.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:citrix:xenserver:6.5:sp1:*:*:*:*:*:*
    • cpe:2.3:a:citrix:xenserver:7.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.