Skip to main content

VSA-2026-040: DLL sideloading vulnerability in XenClean

PublishedUpdatedSeverityCVSS 4.0Affected products
2026-09-142026-09-14🟢 LowNot available yet- XCP-ng Windows Guest Tools
info

A vulnerability was discovered in XenClean that is part of the XCP-ng Windows Guest Tools. We classify the impact as Low. For details on how we assign severity levels, see our Severity Levels Explained page.

Summary​

A vulnerability was discovered in XenClean, which is part of the XCP-ng Windows Guest Tools. The vulnerability allows a sideloaded file to hijack the assembly loading sequence of XenClean and execute untrusted code. This is what VSA-2026-012 was addressing in version 9.1.152 of the tools, but found to be still exploitable by other means.

Status​

  • 2026-09-14: Released

Impact​

The impact is execution of untrusted code. As the XenClean process runs with Administrator privileges, the impact can include local privilege escalation.

Affected Versions​

  • XCP-ng Windows Guest Tools: XenClean in versions before 9.2.385.

Mitigations​

Do not use any affected versions of XenClean.

In general, do not run XenClean or XenBootFix from a directory where untrusted parties can place or modify files.

Only download XenClean from the official releases page.

Resolution​

As of 2026-09-14, XCP-ng Windows Guest Tools version 9.2.385 has been released to address this issue. You can replace any XenClean file you downloaded with version 9.2.385 or later.

List of packages fixing this issue:

  • XCP-ng Windows Guest Tools: version 9.2.385 or later
  • XCP-ng 8.3:
    • xcp-ng-pv-tools: Unlikely to be exploitable through this package, the fix will be integrated later in this package.
info

Users upgrading from 9.2.350 must first install the XenTools-fix-9.2.351.msp hotfix included in the 9.2.385 release before installing 9.2.385, otherwise the upgrade is blocked. No reboot is required after installing the hotfix.

Credits​

Discovered and fixed by Tu Dinh of Vates.

References​