Executive brief
A vulnerability in the VMS operating system allows local users to gain unauthorized administrative privileges. By using a specific system command designed for analyzing process memory dumps, a user can bypass security controls. This could lead to a complete takeover of the system and unauthorized access to sensitive data.
Technical details
A privilege escalation vulnerability exists in VMS versions 4.0 through 5.3 within the ANALYZE/PROCESS_DUMP Digital Command Language (DCL) command. The flaw allows a local, authenticated user to execute the command in a manner that elevates their process privileges. This is a classic local privilege escalation (LPE) where an attacker with low-level access can gain system-level control. The vulnerability was originally identified in 1990 and addressed in subsequent VMS updates. Exploitation requires local access to the DCL interface.
Affected products
- Digital Equipment Corporation (DEC) VMS 4.0 through 5.3
Timeline
- 1990-10-25: advisory: Initial NVD publication and CERT advisory release