CVE-2013-6795

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
24/12/2013
Last modified:
11/04/2025

Description

The Updater in Rackspace Openstack Windows Guest Agent for XenServer before 1.2.6.0 allows remote attackers to execute arbitrary code via a crafted serialized .NET object to TCP port 1984, which triggers the download and extraction of a ZIP file that overwrites the Agent service binary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rackspace:openstack_windows_guest_agent:*:-:-:*:-:xen_server:*:* 1.2.5.0 (including)