CVE-2012-5613
MySQL <5.5.19 & MariaDB <5.5.28a - Privilege Escalation
Title source: llmDescription
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.
Exploits (7)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/35777
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/23179
exploitdb
WORKING POC
VERIFIED
by kingcope · perllocallinux
https://www.exploit-db.com/exploits/23077
metasploit
WORKING POC
EXCELLENT
by kingcope, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/mysql/mysql_mof.rb
metasploit
WORKING POC
EXCELLENT
by sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/mysql/mysql_start_up.rb
References (6)
Scores
EPSS
0.8875
EPSS Percentile
99.5%
Details
CWE
CWE-16
Status
published
Products (2)
mariadb/mariadb
5.5.28a
oracle/mysql
5.5.19
Published
Dec 03, 2012
Tracked Since
Feb 18, 2026