Junglewise Threat Intelligence

CVE-1999-1032: DEC Ultrix privilege escalation in LAT/Telnet Gateway

CVE-1999-1032 · Severity: critical · CVSS 10 · Published 1991-12-31

Technologies: Digital Equipment Corporation (DEC) Ultrix.

Executive brief

A critical vulnerability exists in the LAT/Telnet Gateway component of the Ultrix operating system. This component is responsible for managing network connections between different terminal protocols. An attacker can exploit this flaw to gain full administrative (root) control over the system, potentially leading to complete data theft, system destruction, or unauthorized access to the corporate network.

Technical details

A vulnerability exists in the lattelnet (LAT/Telnet Gateway) utility on DEC Ultrix versions 4.1 and 4.2. The flaw allows an attacker to bypass security controls and escalate privileges to the root level. The attack vector is network-based and does not require prior authentication, as indicated by the CVSS vector AV:N/AC:L/Au:N. Successful exploitation results in a complete compromise of system confidentiality, integrity, and availability. While specific technical details of the memory corruption or logic error are not detailed in the legacy advisory, the impact is a full system takeover. Patches were historically provided by the vendor (Digital Equipment Corporation).

Affected products

  • Digital Equipment Corporation (DEC) Ultrix 4.1, 4.2

Timeline

  • 1991-12-31: disclosed: Initial disclosure via CERT and CIAC bulletins
  • 1991-12-31: advisory: NVD published date

References