Junglewise Threat Intelligence

CVE-1999-1044: Digital UNIX AdvFS local privilege escalation

CVE-1999-1044 · Severity: medium · CVSS 4.6 · Published 1998-05-07

Technologies: Digital Equipment Corporation (DEC) Digital Unix.

Executive brief

A vulnerability in the Advanced File System (AdvFS) utility in Digital UNIX allows local users to gain unauthorized elevated privileges. This utility is responsible for managing file systems on the operating system. An attacker with an existing low-level account could exploit this flaw to take control of the system or access sensitive data.

Technical details

A privilege escalation vulnerability exists in the Advanced File System (AdvFS) utility within Digital UNIX versions 4.0, 4.0a, 4.0b, 4.0c, and 4.0d. The flaw allows a local, authenticated user to execute commands or manipulate files with higher authority than intended, potentially leading to full system compromise. The vulnerability is categorized under NVD-CWE-Other, suggesting a general logic or implementation error in the utility's handling of permissions or execution context. Attackers must have local shell access to exploit this issue. At the time of reporting, patches were typically provided by the vendor (DEC) via specific security bulletins.

Affected products

  • Digital Equipment Corporation (DEC) Digital UNIX 4.0 through 4.0d

Timeline

  • 1998-05-07: disclosed

References