Executive brief
A security vulnerability exists in the mstm utility of the HP-UX operating system, which is used for system diagnostics and monitoring. An individual with existing access to a local user account can exploit this flaw to take full control of the system. This could lead to the unauthorized access of sensitive data, system instability, or the complete compromise of the server's operations.
Technical details
A classic buffer overflow vulnerability exists within the 'mstm' (Support Tool Manager) utility in HP-UX. The flaw is triggered when the application fails to properly validate the length of input data, leading to memory corruption. Because mstm often runs with elevated privileges to perform hardware diagnostics, a local attacker can exploit this overflow to execute arbitrary code with root-level permissions. This is a local privilege escalation (LPE) attack requiring prior access to a non-privileged shell on the target system.
Affected products
- HP HP-UX
Timeline
- 1996-11-01: disclosed: Initial publication date in NVD