{"api_version":"1","generated_at":"2026-07-23T07:56:30+00:00","cve":"CVE-2012-6033","urls":{"html":"https://cve.report/CVE-2012-6033","api":"https://cve.report/api/cve/CVE-2012-6033.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-6033","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-6033"},"summary":{"title":"CVE-2012-6033","description":"The do_tmem_control function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly check privileges, which allows local guest OS users to access control stack operations via unspecified vectors.  NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others.","state":"PUBLISHED","assigner":"mitre","published_at":"2012-11-23 20:55:04","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.4","severity":"","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","baseScore":4.4,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2012/09/05/8","name":"http://www.openwall.com/lists/oss-security/2012/09/05/8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM\n hypercall vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.xen.org/archives/html/xen-announce/2012-09/msg00006.html","name":"http://lists.xen.org/archives/html/xen-announce/2012-09/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"[Xen-announce] Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM hypercall vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://wiki.xen.org/wiki/Security_Announcements#XSA-15_multiple_TMEM_hypercall_vulnerabilities","name":"http://wiki.xen.org/wiki/Security_Announcements#XSA-15_multiple_TMEM_hypercall_vulnerabilities","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Announcements - Xen","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-201309-24.xml","name":"http://security.gentoo.org/glsa/glsa-201309-24.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Xen: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/50472","name":"http://secunia.com/advisories/50472","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA50472 - Xen Multiple Denial of Service and Privilege Escalation Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/78268","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/78268","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/55410","name":"http://www.securityfocus.com/bid/55410","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xen 'TMEM hypercall' Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1027482","name":"http://www.securitytracker.com/id?1027482","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xen Transcendent Memory (TMEM) Multiple Flaws Lets Local Users on the Guest Operating System Gain Elevated Privileges on the Host - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/55082","name":"http://secunia.com/advisories/55082","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA55082 - Gentoo update for xen - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201604-03","name":"https://security.gentoo.org/glsa/201604-03","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xen: Multiple vulnerabilities (GLSA 201604-03) — Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/85199","name":"http://osvdb.org/85199","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-6033","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-6033","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"6033","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"xen","cpe5":"xen","cpe6":"4.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"6033","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"xen","cpe5":"xen","cpe6":"4.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"6033","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"xen","cpe5":"xen","cpe6":"4.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:21:28.366Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"55082","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/55082"},{"name":"1027482","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1027482"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiki.xen.org/wiki/Security_Announcements#XSA-15_multiple_TMEM_hypercall_vulnerabilities"},{"name":"GLSA-201309-24","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-201309-24.xml"},{"name":"55410","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/55410"},{"name":"[oss-security] 20120905 Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM hypercall vulnerabilities","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/09/05/8"},{"name":"xen-tmem-priv-esc(78268)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/78268"},{"name":"85199","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/85199"},{"name":"[Xen-announce] 20120905 Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM hypercall vulnerabilities","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.xen.org/archives/html/xen-announce/2012-09/msg00006.html"},{"name":"50472","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/50472"},{"name":"GLSA-201604-03","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201604-03"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-09-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"The do_tmem_control function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly check privileges, which allows local guest OS users to access control stack operations via unspecified vectors.  NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"55082","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/55082"},{"name":"1027482","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1027482"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiki.xen.org/wiki/Security_Announcements#XSA-15_multiple_TMEM_hypercall_vulnerabilities"},{"name":"GLSA-201309-24","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-201309-24.xml"},{"name":"55410","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/55410"},{"name":"[oss-security] 20120905 Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM hypercall vulnerabilities","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/09/05/8"},{"name":"xen-tmem-priv-esc(78268)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/78268"},{"name":"85199","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/85199"},{"name":"[Xen-announce] 20120905 Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM hypercall vulnerabilities","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.xen.org/archives/html/xen-announce/2012-09/msg00006.html"},{"name":"50472","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/50472"},{"name":"GLSA-201604-03","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201604-03"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-6033","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The do_tmem_control function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly check privileges, which allows local guest OS users to access control stack operations via unspecified vectors.  NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"55082","refsource":"SECUNIA","url":"http://secunia.com/advisories/55082"},{"name":"1027482","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1027482"},{"name":"http://wiki.xen.org/wiki/Security_Announcements#XSA-15_multiple_TMEM_hypercall_vulnerabilities","refsource":"CONFIRM","url":"http://wiki.xen.org/wiki/Security_Announcements#XSA-15_multiple_TMEM_hypercall_vulnerabilities"},{"name":"GLSA-201309-24","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-201309-24.xml"},{"name":"55410","refsource":"BID","url":"http://www.securityfocus.com/bid/55410"},{"name":"[oss-security] 20120905 Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM hypercall vulnerabilities","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/09/05/8"},{"name":"xen-tmem-priv-esc(78268)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/78268"},{"name":"85199","refsource":"OSVDB","url":"http://osvdb.org/85199"},{"name":"[Xen-announce] 20120905 Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM hypercall vulnerabilities","refsource":"MLIST","url":"http://lists.xen.org/archives/html/xen-announce/2012-09/msg00006.html"},{"name":"50472","refsource":"SECUNIA","url":"http://secunia.com/advisories/50472"},{"name":"GLSA-201604-03","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201604-03"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-6033","datePublished":"2012-11-23T20:00:00.000Z","dateReserved":"2012-11-23T00:00:00.000Z","dateUpdated":"2024-08-06T21:21:28.366Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-11-23 20:55:04","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","baseScore":4.4,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:xen:xen:4.0.0:*:*:*:*:*:*:*","matchCriteriaId":"550223A9-B9F1-440A-8C25-9F0F76AF7301"},{"vulnerable":true,"criteria":"cpe:2.3:o:xen:xen:4.1.0:*:*:*:*:*:*:*","matchCriteriaId":"0D532B60-C8DD-4A2F-9D05-E574D23EB754"},{"vulnerable":true,"criteria":"cpe:2.3:o:xen:xen:4.2.0:*:*:*:*:*:*:*","matchCriteriaId":"8F0AF8EF-6FF6-4E22-B16E-82C9F90C6B00"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"6033","Ordinal":"1","Title":"CVE-2012-6033","CVE":"CVE-2012-6033","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"6033","Ordinal":"1","NoteData":"The do_tmem_control function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly check privileges, which allows local guest OS users to access control stack operations via unspecified vectors.  NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others.","Type":"Description","Title":"CVE-2012-6033"},{"CveYear":"2012","CveId":"6033","Ordinal":"2","NoteData":"2012-11-23","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"6033","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}