Junglewise Threat Intelligence

CVE-1999-1198: NeXT NeXTSTEP privilege escalation in BuildDisk

CVE-1999-1198 · Severity: high · CVSS 7.2 · Published 1990-10-03

Technologies: Nextstep, Next. Vendors: Next.

Executive brief

A vulnerability in the BuildDisk utility on older NeXT computer systems allows any user with physical or local access to the machine to gain full administrative control. The program fails to verify administrative credentials before performing sensitive operations, which could lead to unauthorized access to all data on the system or a complete system takeover.

Technical details

The BuildDisk utility in NeXTSTEP versions prior to 2.0 contains a privilege escalation vulnerability. The application does not implement an authentication check or password prompt when executed, despite performing actions that require root-level permissions. A local attacker with standard user access can execute the BuildDisk program to gain unauthorized root privileges. This issue was addressed in NeXTSTEP version 2.0.

Affected products

  • NeXT NeXTSTEP before 2.0

Timeline

  • 1990-10-03: disclosed: Initial publication date
  • 1990-10-03: advisory: NVD published date

References

Related threats