Junglewise Threat Intelligence

CVE-1999-1252: SCO UnixWare privilege escalation via system call

CVE-1999-1252 · Severity: high · CVSS 7.2 · Published 1996-09-04

Vendors: Sco.

Executive brief

A vulnerability in the SCO UnixWare operating system allows local users to bypass security restrictions. By exploiting a flaw in a specific system call, an attacker with basic access to the system can read or modify any file and gain full administrative (root) control. This could lead to a complete compromise of the server and any data stored on it.

Technical details

A vulnerability exists in a specific system call within the SCO UnixWare kernel (versions 2.0.x and 2.1.0). The flaw allows a local, unprivileged user to bypass standard file system permissions. By successfully exploiting this system call, an attacker can read or write to arbitrary files on the system, leading to a full privilege escalation to root. The attack requires local access to the system but no special privileges. Patch information was historically available via SCO security bulletins (SB.96:02a).

Affected products

  • SCO UnixWare 2.0.x, 2.1.0

Timeline

  • 1996-09-04: disclosed: Initial publication date
  • 1996-09-04: advisory: NVD publication date

References