{"id":"CVE-2025-27462","title":"[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]\n\n\nThe Windows PV drivers expose various facilities to userspace","summary":"[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]\n\n\nThe Windows PV drivers expose various facilities to userspace.  Several\nof these have no security descript…","severity":"none","cwe":["CWE-276"],"published":"2026-07-09","updated":"2026-09-29","sourceUpdated":"2026-09-29T19:10:00.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-27462","references":[{"url":"https://xenbits.xen.org/xsa/advisory-468.html","label":"security@xen.org"}],"tags":["nvd"],"epss":0.00158,"epssPercentile":0.04284,"ingestedAt":"2026-09-29T19:44:04.104Z","slug":"CVE-2025-27462","body":"## Overview\n\n[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]\n\n\nThe Windows PV drivers expose various facilities to userspace.  Several\nof these have no security descriptor, and are therefore fully accessible\nto unprivileged users.  These are:\n\n  1. XenCons,  CVE-2025-27462\n  2. XenIface, CVE-2025-27463\n  3. XenBus,   CVE-2025-27464\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}