Junglewise Threat Intelligence

CVE-1999-1209: SCO OpenServer scoterm privilege escalation

CVE-1999-1209 · Severity: high · CVSS 7.2 · Published 1997-11-20

Technologies: Sco Openserver. Vendors: Sco.

Executive brief

A vulnerability in the scoterm terminal emulator allows local users to gain full administrative control (root privileges) over the operating system. This affects legacy SCO OpenServer and Open Desktop systems. An attacker with basic access to the system could exploit this to bypass security controls, access sensitive data, or disrupt operations.

Technical details

A vulnerability exists in the scoterm terminal emulator within SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0. The flaw allows a local, unprivileged user to execute commands with elevated root privileges. While the specific technical root cause (such as a buffer overflow or environment variable manipulation) is not detailed in the provided NVD summary, the impact is a full compromise of confidentiality, integrity, and availability. Exploitation requires local access to the system. Historical references indicate that binary exploits were circulated in the late 1990s.

Affected products

  • SCO OpenServer 5.0
  • SCO Open Desktop/Open Server 3.0

Timeline

  • 1997-11-20: disclosed: Initial publication date in NVD
  • 1997-12-04: other: Exploit binary discussed on Bugtraq mailing list

References

Related threats