Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-4425

33
FAUCET Score

CVE-2012-4425 describes a local privilege escalation vulnerability in libgio, particularly when used in setuid or other privileged programs like spice-gtk. An attacker can exploit this by manipulating the DBUS_SYSTEM_BUS_ADDRESS environment variable to execute arbitrary code. With a CVSS score of 6.9 (AV:L/AC:M/Au:N/C:C/I:C/A:C), this vulnerability has high impact on confidentiality, integrity, and availability, but requires local access and medium attack complexity. While not actively exploited in the wild and lacking Metasploit/Nuclei modules, an ExploitDB entry (EDB-21323) exists, indicating public exploit code availability. Community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:freedesktop:spice-gtk:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:gtk:libgio:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.9MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.09%
Probability of exploitation in next 30 days
EPSS Percentile
62.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-21323 · Jul 17, 2012
This CVE's current EPSS score of 0.0109 is in the 91st percentile among its peer group of 1,595 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: spice-gtk-0:0.11-11.el6_3.1
View patch

Vendor Advisories (1)

redhatCVE-2012-4425Moderate

spice-gtk/glib: Possible privilege escalation via un-sanitized environment variable

Sep 12, 2012

References

permalink.gmane.org / gmane.linux.redhat.fedora.extras.cvs/853051
Patch
rhn.redhat.com / errata/RHSA-2012-1284.html
bugzilla.redhat.com / show_bug.cgi
exploit-db.com / exploits/21323
Exploit
openwall.com / lists/oss-security/2012/09/12/6
openwall.com / lists/oss-security/2012/09/14/2
openwall.com / lists/oss-security/2012/09/17/2
securityfocus.com / bid/55555
spinics.net / lists/spice-devel/msg01940.html
Exploit