PoC Index

CVE-2012-3485

HIGH 7.2EPSS 3.8%

Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname, which allows local users to gain privileges via an execl system call.

CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
3.78% chance of exploitation in the next 30 days, 89th percentile
Published
2012-08-26
Updated
2024-08-06

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (2)

References

Related