CVE Feed

    Dashboard / CVE / CVE-2012-0217

    CVE-2012-0217

    The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.

    Published:Jun 12, 2012
    Last Modified:Apr 11, 2025
    EPS:Jun 12, 2012
    EPSS Score:0.87414
    CVSS Score:7.2

    Affected Products

    Vendor
    Citrix
    Product
    Xenserver
    Vendor
    Freebsd
    Product
    Freebsd
    Vendor
    Illumos
    Product
    Illumos
    Vendor
    Joyent
    Product
    Smartos
    Vendor
    Microsoft
    Product
    Windows 7
    Vendor
    Microsoft
    Product
    Windows Server 2003
    Vendor
    Microsoft
    Product
    Windows Server 2008
    Vendor
    Microsoft
    Product
    Windows Xp
    Vendor
    Netbsd
    Product
    Netbsd
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Rhel Eus
    Vendor
    Sun
    Product
    Sunos
    Vendor
    Xen
    Product
    Xen

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High