Executive brief
A vulnerability in the Volume Management daemon (vold) of the Solaris operating system allows local users to gain full administrative control of the system. This component is responsible for managing removable media like CD-ROMs and floppy disks. An attacker with basic access to the machine could exploit this flaw to bypass security restrictions, access sensitive data, or disrupt operations.
Technical details
A privilege escalation vulnerability exists in the Volume Management daemon (vold) within Sun Solaris 2.x. The flaw allows a local, unprivileged user to execute commands or manipulate files with root-level permissions. While the specific technical root cause (such as a buffer overflow or race condition) is not detailed in the provided NVD record, the impact is a complete compromise of confidentiality, integrity, and availability (CVSS 7.2). Attackers must have local shell access to the system to exploit this vulnerability.
Affected products
- Sun Microsystems Solaris 2.x
Timeline
- 1996-08-06: disclosed: NVD Published Date