Lucene search

K
redhatcveRedhat.comRH:CVE-2020-27674
HistoryOct 23, 2020 - 7:04 p.m.

CVE-2020-27674

2020-10-2319:04:57
redhat.com
access.redhat.com
15

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

5.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

0.0005 Low

EPSS

Percentile

17.6%

A flaw was found in the Xen hypercalls with INVLPG-like behavior used by x86 PV guests to invalidate TLB entries. This flaw allows a malicious unprivileged guest user to escalate their privileges to the kernel level within the guest.

Mitigation

There is no known mitigation for this flaw apart from applying the patch.

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

5.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

0.0005 Low

EPSS

Percentile

17.6%