Junglewise Threat Intelligence

CVE-1999-1144: HP HP-UX MPower privilege escalation via insecure file permissions

CVE-1999-1144 · Severity: high · CVSS 7.2 · Published 1997-01-30

Vendors: Hp.

Executive brief

A security issue in the HP-UX MPower software suite allows local users to gain unauthorized administrative control over the system. This occurs because certain system files were installed with incorrect security settings, allowing standard users to modify or access sensitive data. An attacker with basic access to the machine could exploit this to take full control of the operating system, potentially leading to data theft or service disruption.

Technical details

The vulnerability stems from insecure file system permissions (CWE-Other) assigned to specific files within the HP MPower application on HP-UX 10.x. Because these files are world-writable or otherwise improperly restricted, a local attacker with shell access can modify system-critical files or binaries. This leads to a complete compromise of confidentiality, integrity, and availability (CVSS 7.2) as the attacker can escalate privileges to root. The issue was originally identified in HP Security Bulletin HPSBUX9701-051.

Affected products

  • HP MPower HP-UX 10.x

Timeline

  • 1997-01-30: disclosed: Original publication date of the vulnerability.
  • 1997-01-30: advisory: NVD published date.

References