Advisory 61

Advisory 61: Citrix Releases Security Updates for XenServer and Citrix Hypervisor

Release Date: 12 of April 2024

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provide the following advisory.

What is it?

XenServer and Citrix Hypervisor Security Updates for CVE- 2023-46842, CVE-2024-2201 and CVE-2024-31142. Two issues have been identified that affect XenServer and Citrix Hypervisor.

CVE-2024-2201 – only affects deployments that use Intel CPUs while
CVE-2024-31142 – only affects deployments that use AMD CPUs.
CVE-2023-46842 – allows malicious privileged code running in a guest VM to cause the host to crash.  

References

  1. https://support.citrix.com/article/CTX588044/hotfix-xs82ecu1062-for-citrix-hypervisor-82-cumulative-update-1
  2. https://support.citrix.com/article/CTX633151/xenserver-and-citrix-hypervisor-security-update-for-cve202346842-cve20242201-and-cve202431142
  3. https://support.citrix.com/article/CTX588044/hotfix-xs82ecu1062-for-citrix-hypervisor-82-cumulative-update-1