Junglewise Threat Intelligence

CVE-1999-1197: Sun Microsystems SunOS privilege escalation in TIOCCONS

CVE-1999-1197 · Severity: high · CVSS 7.2 · Published 1990-12-20

Technologies: Sunos. Vendors: Sun Microsystems, Sun.

Executive brief

A vulnerability in the SunOS operating system allows a local user to improperly redirect console input and output. This flaw could be exploited by an authorized user on the system to gain elevated administrative privileges, potentially leading to full control over the machine and its data.

Technical details

The vulnerability exists within the TIOCCONS ioctl function in SunOS 4.1.1. The system fails to perform adequate permission checks when a user requests to redirect console I/O to a different terminal. A local attacker with standard user access can exploit this lack of validation to intercept sensitive console traffic or manipulate system inputs, ultimately facilitating a privilege escalation to root. This is a local attack requiring no special preconditions other than system access. Patch information was historically provided in CERT advisory CA-1990-12.

Affected products

  • Sun Microsystems SunOS 4.1.1

Timeline

  • 1990-12-20: advisory: Initial NVD publication and CERT advisory release

References

Related threats