CVE-2012-4425 describes a local privilege escalation vulnerability in libgio, particularly when used in setuid or other privileged programs like spice-gtk. An attacker can exploit this by manipulating the DBUS_SYSTEM_BUS_ADDRESS environment variable to execute arbitrary code. With a CVSS score of 6.9 (AV:L/AC:M/Au:N/C:C/I:C/A:C), this vulnerability has high impact on confidentiality, integrity, and availability, but requires local access and medium attack complexity. While not actively exploited in the wild and lacking Metasploit/Nuclei modules, an ExploitDB entry (EDB-21323) exists, indicating public exploit code availability. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:freedesktop:spice-gtk:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:gtk:libgio:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.