CVE-2012-3490 describes a privilege escalation vulnerability in Condor versions 7.6.x before 7.6.10 and 7.8.x before 7.8.4. Specifically, the my_popenv_impl, my_spawnv, and systemCommand functions fail to properly validate setuid call return values, potentially allowing subprocesses to run with root privileges. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk. It can be exploited remotely with low attack complexity and low privileges, leading to high impacts on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor are there public exploit modules available in Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.6.0, < 7.6.10CPE matchmatch criteria | cpe:2.3:a:wisc:htcondor:*:*:*:*:*:*:*:* | ||
>= 7.8.0, < 7.8.4CPE matchmatch criteria | cpe:2.3:a:wisc:htcondor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.