Junglewise Threat Intelligence

CVE-1999-1134: HP Vue 3.0 privilege escalation in HP-UX 9.x

CVE-1999-1134 · Severity: high · CVSS 7.2 · Published 1994-05-18

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A security vulnerability in the HP Visual User Environment (VUE) on older HP-UX systems allows a local user to bypass security restrictions. If exploited, a standard user could gain full administrative (root) control over the workstation. This could lead to a complete compromise of the system, including unauthorized access to all data and the ability to modify or disable system operations.

Technical details

A privilege escalation vulnerability exists in HP Vue 3.0 running on HP-UX 9.x. The flaw allows a local, unauthenticated user to execute commands with elevated privileges, ultimately leading to a full root compromise of the affected host. While the specific technical root cause (such as a buffer overflow or insecure file handling) is not detailed in the legacy advisory, the impact is a complete loss of confidentiality, integrity, and availability. The issue has been addressed by HP through patches PHSS_4038, PHSS_4055, and PHSS_4066.

Affected products

  • HP Vue 3.0 HP-UX 9.x

Timeline

  • 1994-05-18: disclosed
  • 1994-05-18: advisory

References

Related threats