CVE-2012-0217 describes a privilege escalation vulnerability in the x86-64 kernel system-call functionality across various operating systems, including Xen, Citrix XenServer, Oracle Solaris, illumos, SmartOS, FreeBSD, NetBSD, and Microsoft Windows. This flaw arises from the incorrect use of the sysret path on Intel processors when a specific address is not canonical, allowing local users to gain elevated privileges via a crafted application. The vulnerability has a CVSS score of 7.2, indicating high severity with local access required and low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Its EPSS score of 0.88 suggests a high likelihood of exploitation. Exploit code for CVE-2012-0217 is publicly available, with Metasploit modules and ExploitDB entries specifically targeting FreeBSD and Windows. While not listed on the KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating its historical relevance and the availability of exploitation resources.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* | ||
<= r13723CPE matchmatch criteria | cpe:2.3:o:illumos:illumos:*:*:*:*:*:*:*:* | ||
<= 20120614CPE matchmatch criteria | cpe:2.3:o:joyent:smartos:*:*:*:*:*:*:*:* | ||
<= 4.1.2CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:4.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.