Privilege Escalation
ESC12 - YubiHSM2
Vulnerability in certificate authorities using YubiHSM key storage provider allowing CA private key extraction
ESC12 is a vulnerability disclosed by Hans-Joachim Knobloch in this blogpost, which details a vulnerability in certificate authorities that stores their private key with the YubiHSM key storage provider. When this occurs, anyone with local unprivileged access to the CA server can extract the CA private key and forge arbitrary certificates to elevate their privileges.