Junglewise Threat Intelligence

CVE-1999-0094: IBM AIX privilege escalation in piodmgrsu command

CVE-1999-0094 · Severity: medium · CVSS 4.6 · Published 1997-10-29

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A vulnerability in the IBM AIX operating system allows a local user to gain unauthorized group privileges. By exploiting the piodmgrsu command, an attacker who already has access to the system can elevate their permissions, potentially accessing or modifying sensitive files and data they should not be able to reach. This could lead to a breach of confidentiality and integrity on the affected server.

Technical details

The piodmgrsu command in IBM AIX contains a vulnerability that allows for local privilege escalation. A local attacker with standard user access can execute this command to gain the privileges of additional system groups. The root cause is likely improper permission handling or a flaw in the setuid/setgid implementation of the piodmgrsu utility. Successful exploitation allows the attacker to bypass intended access controls and perform actions with elevated group-level authority. This issue was originally identified in 1997.

Affected products

  • IBM AIX

Timeline

  • 1997-10-29: disclosed: Initial publication date

References

Related threats