CVE-2012-5613

MySQL <5.5.19 & MariaDB <5.5.28a - Privilege Escalation

Title source: llm

Description

MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.

Exploits (7)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/35777
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/23179
exploitdb WORKING POC VERIFIED
by kingcope · perllocallinux
https://www.exploit-db.com/exploits/23077
nomisec WORKING POC 3 stars
by Hood3dRob1n · poc
https://github.com/Hood3dRob1n/MySQL-Fu.rb
nomisec WORKING POC
by w4fz5uck5 · poc
https://github.com/w4fz5uck5/UDFPwn-CVE-2012-5613
metasploit WORKING POC EXCELLENT
by kingcope, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/mysql/mysql_mof.rb
metasploit WORKING POC EXCELLENT
by sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/mysql/mysql_start_up.rb

Scores

EPSS 0.8875
EPSS Percentile 99.5%

Details

CWE
CWE-16
Status published
Products (2)
mariadb/mariadb 5.5.28a
oracle/mysql 5.5.19
Published Dec 03, 2012
Tracked Since Feb 18, 2026