Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-4347Improper Privilege Management in Kernel

Severity
6.9MEDIUMNVD
EPSS
5.9%
top 9.35%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 22
Latest updateMay 13

Description

The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init function in drivers/acpi/debugfs.c.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vpxp-m77w-89hf: The ACPI subsystem in the Linux kernel before 22022-05-13
CVEList
CVE-2010-4347: The ACPI subsystem in the Linux kernel before 22010-12-22

💥Exploits & PoCs

1
Exploit-DB
Linux Kernel < 2.6.37-rc2 - 'ACPI custom_method' Local Privilege Escalation2010-12-18

📋Vendor Advisories

2
Red Hat
kernel: /sys/kernel/debug/acpi/custom_method can bypass module restrictions2011-02-22
Red Hat
kernel: local privilege escalation via /sys/kernel/debug/acpi/custom_method2010-11-13

💬Community

1
Bugzilla
CVE-2010-4347 kernel: local privilege escalation via /sys/kernel/debug/acpi/custom_method2010-12-16
CVE-2010-4347 — Improper Privilege Management in Kernel | cvebase