The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.
2012-06-12T22:55:01.343
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | freebsd | freebsd | ≤ 9.0 | Yes |
Operating System | illumos | illumos | ≤ r13723 | Yes |
Operating System | joyent | smartos | ≤ 20120614 | Yes |
Operating System | xen | xen | ≤ 4.1.2 | Yes |
Operating System | xen | xen | 4.0.0 | Yes |
Operating System | xen | xen | 4.0.1 | Yes |
Operating System | xen | xen | 4.0.2 | Yes |
Operating System | xen | xen | 4.0.3 | Yes |
Operating System | xen | xen | 4.0.4 | Yes |
Operating System | xen | xen | 4.1.0 | Yes |
Operating System | xen | xen | 4.1.1 | Yes |
Operating System | microsoft | windows_7 | * | Yes |
Operating System | microsoft | windows_7 | * | Yes |
Operating System | microsoft | windows_server_2003 | * | Yes |
Operating System | microsoft | windows_server_2008 | r2 | Yes |
Operating System | microsoft | windows_xp | * | Yes |
Application | citrix | xenserver | ≤ 6.0.2 | Yes |
Application | citrix | xenserver | 6.0 | Yes |
Operating System | netbsd | netbsd | ≤ 6.0 | Yes |
Operating System | sun | sunos | ≤ 5.11 | Yes |