Junglewise Threat Intelligence

CVE-1999-0130: Sendmail local privilege escalation via daemon mode

CVE-1999-0130 · Severity: high · CVSS 7.2 · Published 1996-11-16

Technologies: Sendmail.

Executive brief

A vulnerability in the Sendmail email routing software allows local users to gain full administrative control over the system. By starting the application in a specific background mode, an attacker can bypass security restrictions to execute commands with root-level privileges. This could lead to a complete system takeover, data theft, or permanent disruption of services.

Technical details

A privilege escalation vulnerability exists in Sendmail when handled by local users. The flaw allows an unprivileged user to invoke the Sendmail binary with specific flags to start it in daemon mode. Due to improper validation or dropped privileges during this process, the attacker can transition from a standard user account to root privileges. This is a local attack requiring shell access to the target machine. Successful exploitation results in full compromise of the host operating system.

Affected products

  • Sendmail Sendmail

Timeline

  • 1996-11-16: disclosed

References