Executive brief
A vulnerability in the Support Watch utility on HP-UX systems allows local users to gain unauthorized elevated privileges. Support Watch is a diagnostic tool used for system monitoring and maintenance. An attacker with existing access to the system could exploit this flaw to take control of the operating system, potentially compromising sensitive data or system stability.
Technical details
This is a privilege escalation vulnerability within the Support Watch (SupportWatch) component of HP-UX versions 8.0 through 9.0. The flaw allows a local user with standard access to execute commands or manipulate the system with higher-level permissions. While the specific technical root cause (such as a buffer overflow or insecure file handling) is not detailed in the legacy advisory, the impact is a compromise of system integrity and confidentiality. The vulnerability is exploitable locally without prior authentication beyond initial system access. HP released an advisory (HPSBUX9411-019) to address this issue.
Affected products
- HP HP-UX 8.0 through 9.0
Timeline
- 1994-11-30: disclosed: Initial publication of the vulnerability details.