Oval Definition:oval:org.mitre.oval:def:15596
Revision Date:2012-07-30Version:49
Title:User Mode Scheduler Memory Corruption Vulnerability (CVE-2012-0217)
Description:The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2012-0217
Platform(s):Microsoft Windows 7
Microsoft Windows Server 2008 R2
Product(s):
Definition Synopsis
  • Win7/2k8 R2 and vulnerable file version
  • Win7/2K8 R2 (X64)
  • Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • AND Check for LDR/GDR
  • Check if the version of ntoskrnl.exe is less than 6.1.7600.17017
  • OR Check for LDR
  • the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000
  • AND Check if the version of ntoskrnl.exe is less than 6.1.7600.21207
  • OR Win7 SP1/Win2k8 R2 SP1
  • Win7 SP1/Win 2K8 R2 SP1
  • Microsoft Windows 7 x64 Service Pack 1 is installed
  • OR Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed
  • AND Check for LDR/GDR
  • Check if the version of Ntoskrnl.exe is less than 6.1.7601.17835
  • OR Check for LDR
  • Check if the version of Ntoskrnl.exe is less than 6.1.7601.21987
  • AND the version of Ntoskrnl.exe is greater than or equal 6.1.7601.21000
  • BACK