Junglewise Threat Intelligence

CVE-1999-1135: HP VUE privilege escalation in HP-UX 9.x

CVE-1999-1135 · Severity: high · CVSS 7.2 · Published 1994-04-20

Technologies: Hp-Ux. Vendors: Hp.

Executive brief

A vulnerability in the Visual User Environment (VUE) on HP-UX 9.x systems allows a local user to bypass security restrictions and gain full administrative (root) control. This could lead to a complete compromise of the system, including unauthorized access to all data and the ability to disrupt operations. The issue has been addressed in specific software patches provided by the vendor.

Technical details

A privilege escalation vulnerability exists in HP Visual User Environment (VUE) 3.0 running on HP-UX 9.x. The flaw allows a local, unprivileged user to execute commands with elevated root privileges. While the specific technical root cause (such as a buffer overflow or insecure file handling) is not detailed in the legacy advisory, the impact is a total loss of confidentiality, integrity, and availability. The vulnerability is resolved by applying vendor patches PHSS_4994 and PHSS_5438.

Affected products

  • HP VUE 3.0 HP-UX 9.x

Timeline

  • 1994-04-20: disclosed: Initial publication date
  • 1994-04-20: advisory

References

Related threats