CVE-2004-1054
AIX 5.3.0 - 'invscout' Local Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.
Vulnerabilidad de camino de ejecución no confiable en invscout de IBM AIX 5.1.0, 5.2.0 y 5.3.0 permite a usuarios locales ganar privilegios modificando la variable de entorno PATH para que apunte a un programa "uname" malicioso, que es ejecutado desde lsvpd después de que lsvpd haya sido ejecutado por invscout
Local exploitation of an untrusted path vulnerability in the invscout command included by default in multiple versions of IBM Corp.'s AIX could allow attackers to execute arbitrary code as the root user. Verified in version 5.2.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2004-11-18 CVE Reserved
- 2004-12-22 CVE Published
- 2005-03-25 First Exploit
- 2024-08-08 CVE Updated
- 2025-06-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/18619 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/36794 | 2005-03-25 | |
https://www.exploit-db.com/exploits/898 | 2005-03-25 | |
https://www.exploit-db.com/exploits/701 | 2017-01-30 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 5.1 Search vendor "Ibm" for product "Aix" and version "5.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 5.1l Search vendor "Ibm" for product "Aix" and version "5.1l" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 5.2 Search vendor "Ibm" for product "Aix" and version "5.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 5.2.2 Search vendor "Ibm" for product "Aix" and version "5.2.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 5.2_l Search vendor "Ibm" for product "Aix" and version "5.2_l" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 5.3 Search vendor "Ibm" for product "Aix" and version "5.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Aix Search vendor "Ibm" for product "Aix" | 5.3_l Search vendor "Ibm" for product "Aix" and version "5.3_l" | - |
Affected
|