Junglewise Threat Intelligence

CVE-1999-0117: IBM AIX privilege escalation in passwd

CVE-1999-0117 · Severity: high · CVSS 7.2 · Published 1992-03-31

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A vulnerability in the password management utility of the IBM AIX operating system allows standard users to bypass security restrictions. By exploiting this flaw, a person with local access to the system can gain full administrative (root) control. This could lead to a total compromise of the server, including unauthorized access to sensitive data and the ability to disrupt critical business operations.

Technical details

A privilege escalation vulnerability exists in the 'passwd' command within IBM AIX. The flaw allows a local, unprivileged user to execute arbitrary code or manipulate system files with elevated privileges, ultimately resulting in full root access. While the specific technical root cause (such as a buffer overflow or insecure file handling) is not detailed in the legacy advisory, the impact is a complete compromise of system confidentiality, integrity, and availability. The attack requires local shell access but no special administrative permissions. Users should apply legacy patches or migrate to supported versions of AIX where this behavior is corrected.

Affected products

  • IBM AIX

Timeline

  • 1992-03-31: disclosed

References

Related threats