CVE-2019-5596
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.2%
from disclosure to weapon148 days
Published on NVDFeb 12
1st PoC+148d
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released potentially allowing a malicious local user to gain root privileges or escape from a jail.
Affected products
FreeBSD · FreeBSDpublic PoCs found — 4✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47829exploitdbwww.exploit-db.com/exploits/47081unverifiedgithubgithub.com/raymontag/CVE-2019-5596★ 1cve_referencepacketstormsecurity.com/files/155790/FreeBSD-fd-Privilege-Escalation.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.