CVE-2012-0217

N/A Unknown
Published: June 12, 2012 Modified: April 29, 2026
View on NVD

Description

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/55082
Source: security@debian.org
http://www.kb.cert.org/vuls/id/649219
Source: security@debian.org
US Government Resource
http://www.us-cert.gov/cas/techalerts/TA12-164A.html
Source: security@debian.org
US Government Resource
https://www.illumos.org/issues/2873
Source: security@debian.org
http://blog.illumos.org/2012/06/14/illumos-vulnerability-patched/
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/55082
Source: af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-201309-24.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://smartos.org/2012/06/15/smartos-news-3/
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.citrix.com/article/CTX133161
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2012/dsa-2501
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2012/dsa-2508
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.kb.cert.org/vuls/id/649219
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.us-cert.gov/cas/techalerts/TA12-164A.html
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
https://bugzilla.redhat.com/show_bug.cgi?id=813428
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/28718/
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/46508/
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.illumos.org/issues/2873
Source: af854a3a-2127-422b-91ae-364da2661108

46 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
37.2%
98th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

xen citrix joyent microsoft sun illumos netbsd freebsd