The Shittrix Disclosure: 89 Flaws Collapse 20 Years of Trust in Citrix and XCP-ng
ID: 4c8f4cb5-e9ca-5af7-a6ff-b6eb3067b24f
STIX ID: report--4c8f4cb5-e9ca-5af7-a6ff-b6eb3067b24f
Feed Name: securityonline.info
Independent researcher Jakob Wolffhechel disclosed 89 vulnerabilities in Citrix XenServer/Hypervisor and XCP-ng (dubbed “Shittrix”), describing pervasive input-validation failures since ~2006 that let minimally privileged management users execute single API calls to gain full host filesystem access, mount any host block device, proxy malformed storage-protocol commands, exfiltrate cross-VM data, and potentially install persistent bootkits; key issues (e.g., BOC-1, SMC-1) are rated CVSS 9.9 and the researcher recommends treating any production host exposed during the 20-year window as compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
