6.9
CVSSv2

CVE-2010-4347

Published: 22/12/2010 Updated: 13/02/2023
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The ACPI subsystem in the Linux kernel prior to 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init function in drivers/acpi/debugfs.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

opensuse opensuse 11.3

suse linux enterprise real time extension 11

Exploits

/* * american-sign-languagec * * Linux Kernel < 2637-rc2 ACPI custom_method Privilege Escalation * Jon Oberheide <jon@oberheideorg> * jonoberheideorg * * Information: * * cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2010-4347 * * This custom_method file allows to inject custom ACPI methods into the ACPI * ...
Linux kernel versions prior to 2637-rc2 ACPI custom_method local root privilege escalation exploit ...