Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-0217

65
FAUCET Score

CVE-2012-0217 describes a privilege escalation vulnerability in the x86-64 kernel system-call functionality across various operating systems, including Xen, Citrix XenServer, Oracle Solaris, illumos, SmartOS, FreeBSD, NetBSD, and Microsoft Windows. This flaw arises from the incorrect use of the sysret path on Intel processors when a specific address is not canonical, allowing local users to gain elevated privileges via a crafted application. The vulnerability has a CVSS score of 7.2, indicating high severity with local access required and low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Its EPSS score of 0.88 suggests a high likelihood of exploitation. Exploit code for CVE-2012-0217 is publicly available, with Metasploit modules and ExploitDB entries specifically targeting FreeBSD and Windows. While not listed on the KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating its historical relevance and the availability of exploitation resources.

Impacted Technologies

VendorProductVersion(s)CPE
<= 9.0CPE matchmatch criteria
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
<= r13723CPE matchmatch criteria
cpe:2.3:o:illumos:illumos:*:*:*:*:*:*:*:*
<= 20120614CPE matchmatch criteria
cpe:2.3:o:joyent:smartos:*:*:*:*:*:*:*:*
<= 4.1.2CPE matchmatch criteria
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:o:xen:xen:4.0.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
37.21%
Probability of exploitation in next 30 days
EPSS Percentile
98.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Metasploit: FreeBSD Intel SYSRET Privilege Escalation · Jun 12, 2012
ExploitDB: EDB-46508 · Mar 7, 2019
This CVE's current EPSS score of 0.3721 is in the 100th percentile among its peer group of 3,237 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-308.8.2.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.6 EUS - Server OnlyFixed in: kernel-0:2.6.18-238.39.1.el5
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-xen

Vendor Advisories (1)

redhatCVE-2012-0217Important

kernel: x86-64: avoid sysret to non-canonical address

Jun 12, 2012

References

blog.illumos.org / 2012/06/14/illumos-vulnerability-patched
blog.xen.org / index.php/2012/06/13/the-intel-sysret-privilege-escalation
ftp.netbsd.org / pub/NetBSD/security/advisories/NetBSD-SA2012-003.txt.asc
lists.xen.org / archives/html/xen-announce/2012-06/msg00001.html
lists.xen.org / archives/html/xen-devel/2012-06/msg01072.html
bugzilla.redhat.com / show_bug.cgi
docs.microsoft.com / en-us/security-updates/securitybulletins/2012/ms12-042
secunia.com / advisories/55082
security.freebsd.org / advisories/FreeBSD-SA-12:04.sysret.asc
security.gentoo.org / glsa/glsa-201309-24.xml
smartos.org / 2012/06/15/smartos-news-3
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15596
support.citrix.com / article/CTX133161
exploit-db.com / exploits/28718
exploit-db.com / exploits/46508
illumos.org / issues/2873
wiki.smartos.org / display/DOC/SmartOS+Change+Log
debian.org / security/2012/dsa-2501
debian.org / security/2012/dsa-2508
kb.cert.org / vuls/id/649219
US Government Resource
mandriva.com / security/advisories
oracle.com / technetwork/topics/security/cpuoct2012-1515893.html
us-cert.gov / cas/techalerts/TA12-164A.html
US Government Resource