CVE-2012-0217

CVSS 7.2 - HIGH
Description

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.

Affected Products
20
Vendor Product Version
freebsd freebsd All versions
illumos illumos All versions
joyent smartos All versions
xen xen All versions
xen xen 4.0.0
xen xen 4.0.1
xen xen 4.0.2
xen xen 4.0.3
xen xen 4.0.4
xen xen 4.1.0
xen xen 4.1.1
microsoft windows_7 All versions
microsoft windows_7 All versions
microsoft windows_server_2003 All versions
microsoft windows_server_2008 r2
microsoft windows_xp All versions
citrix xenserver All versions
citrix xenserver 6.0
netbsd netbsd All versions
sun sunos All versions
Weakness Types
CWE-119
CVE Information
CVE ID:
CVE-2012-0217
Published:
2012-06-12
Modified:
2026-04-29
CVSS Score:
7.2
Severity:
HIGH
Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
Affected Vendors
joyent netbsd microsoft illumos sun freebsd xen citrix
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL