Intel CPU Hardware Local Privilege Escalation Vulnerability
BID:53856
Info
Intel CPU Hardware Local Privilege Escalation Vulnerability
| Bugtraq ID: | 53856 |
| Class: | Unknown |
| CVE: |
CVE-2012-0217 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 12 2012 12:00AM |
| Updated: | Apr 13 2015 10:19PM |
| Credit: | Rafal Wojtczuk of Bromium and Jan Beulich of SUSE |
| Vulnerable: |
XenSource Xen 4.1.2 XenSource Xen 4.1.1 XenSource Xen 4.0 XenSource Xen 3.4 Sun Solaris 11 Sun Solaris 10 S.u.S.E. openSUSE 12.1 Redhat Enterprise Linux EUS 5.6.z server Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 5 NetBSD NetBSD 5.1 NetBSD NetBSD 5.0 NetBSD NetBSD 4.1 NetBSD NetBSD 4.0 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 R2 for x64-based Systems 0 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for x64-based Systems 0 Intel Hybrid Cloud Platform 3.1.1 Intel Hybrid Cloud Platform 3.1 Intel Hybrid Cloud Platform 3.0 Intel Hybrid Cloud Platform 2.5 Gentoo Linux FreeBSD FreeBSD 9.0 FreeBSD FreeBSD 8.3 FreeBSD FreeBSD 8.2 FreeBSD FreeBSD 8.1 FreeBSD FreeBSD 7.4 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Bsdperimeter pfSense 2.0.1 Bsdperimeter pfSense 2.0 Avaya IR 4.0 Avaya CMS R16 Avaya CMS r15 Avaya Call Management System R16.3 Avaya Call Management System R16.2 Avaya Call Management System R16.1 Avaya Call Management System R 16 Avaya Call Management System R 15 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.2 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 |
| Not Vulnerable: |
Bsdperimeter pfSense 2.0.2 Avaya IR 4.0 Service Pack 6 Avaya CMS R16.3 Avaya Aura System Platform 6.3 |
Discussion
Intel CPU Hardware Local Privilege Escalation Vulnerability
64-bit operating systems and virtualization software running on Intel CPU hardware are prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to escalate privileges and execute arbitrary code with kernel-level privileges or to do a guest-to-host virtual machine escape.
Note: This issue was previously titled 'Microsoft Windows User Mode Scheduler Local Privilege Escalation Vulnerability' but has been updated to better document the underlying issue.
64-bit operating systems and virtualization software running on Intel CPU hardware are prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to escalate privileges and execute arbitrary code with kernel-level privileges or to do a guest-to-host virtual machine escape.
Note: This issue was previously titled 'Microsoft Windows User Mode Scheduler Local Privilege Escalation Vulnerability' but has been updated to better document the underlying issue.
Exploit / POC
Intel CPU Hardware Local Privilege Escalation Vulnerability
The following exploits are available:
http://packetstormsecurity.org/files/download/115908/sysret.rar
The following exploits are available:
http://packetstormsecurity.org/files/download/115908/sysret.rar
Solution / Fix
Intel CPU Hardware Local Privilege Escalation Vulnerability
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows 7 for x64-based Systems 0
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows 7 for x64-based Systems SP1
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2709715)
http://www.microsoft.com/downloads/details.aspx?familyid=c2b47091-534f -41c3-a229-b5a9ec4b64bb
Microsoft Windows 7 for x64-based Systems 0
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2709715)
http://www.microsoft.com/downloads/details.aspx?familyid=c2b47091-534f -41c3-a229-b5a9ec4b64bb
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB2709715)
http://www.microsoft.com/downloads/details.aspx?familyid=1696726a-ed04 -4c0e-b9b6-3ac4ac775c4c
References
Intel CPU Hardware Local Privilege Escalation Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- pfSense 2.0.2 Release Now Available (BSD Perimeter)
- Privilege escalation when returning from kernel (FreeBSD)
- Vulnerability Note VU#649219 SYSRET 64-bit operating system privilege escalation (US-CERT)
- [Xen-announce] Xen Security Advisory 7 (CVE-2012-0217) - PV privilege escalation (XenSource)
- ASA-2012-300: kernel security update (RHSA-2012-0721) (Avaya)
- ASA-2012-463 Oracle Solaris Critical Update (Avaya)
- Microsoft Security Bulletin MS12-042 (Microsoft)
- NetBSD Security Advisory 2012-003 (NetBSD)
- Oracle Critical Patch Update Advisory - October 2012 (Oracle)
- Oracle Solaris Critical Update (CVE-2012-3210 CVE-2012-0217 CVE-2012-3187 CVE-20 (Avaya)
- Privilege Escalation in Intel® Hybrid Cloud (IHC) : INTEL-SA-00032 (Intel)