CVE-2019-3010
Oracle Solaris Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
YesDecision
Descriptions
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Una vulnerabilidad en el producto Oracle Solaris de Oracle Systems (componente: XScreenSaver). La versión compatible que está afectada es la 11. Una vulnerabilidad fácilmente explotable permite a un atacante poco privilegiado con inicio de sesión en la infraestructura donde es ejecutado Oracle Solaris comprometer a Oracle Solaris. Aunque la vulnerabilidad se encuentre en Oracle Solaris, los ataques pueden impactar significativamente a productos adicionales. Los ataques con éxito de esta vulnerabilidad pueden resultar en la toma de control de Oracle Solaris. CVSS 3.0 Puntuación Base 8.8 (Impactos de la Confidencialidad, Integridad y Disponibilidad). Vector CVSS: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2018-12-14 CVE Reserved
- 2019-10-16 CVE Published
- 2019-10-21 First Exploit
- 2022-05-25 Exploited in Wild
- 2022-06-15 KEV Due Date
- 2024-09-30 CVE Updated
- 2024-10-09 EPSS Updated
CWE
CAPEC
References (8)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/47529 | 2019-10-21 | |
http://packetstormsecurity.com/files/154960/Solaris-xscreensaver-Privilege-Escalation.html | 2024-09-30 |
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html | 2023-01-31 |
URL | Date | SRC |
---|