Citrix Security Updates – 28 May 2025

Citrix has released security updates to address multiple vulnerabilities affecting Citrix XenServer and Citrix Hypervisor.

The addressed vulnerabilities could allow the local attacker to gain elevated privileges by exposing various facilities to userspace by the XenBus, XenCons, and XenIface drivers.

Sample of the addressed vulnerabilities:

XenServer and Citrix Hypervisor Privilege Escalation Vulnerability (CVE-2025- 27462):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privilege
Vulnerabilities
  • CVE-2024-5491
  • CVE-2024-5492
  • CVE-2024-28956
  • CVE-2025-27462
  • CVE-2025-27463
  • CVE-2025-27464
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Citrix Security Updates

References