Junglewise Threat Intelligence

CVE-1999-1305: SCO UNIX privilege escalation in at program

CVE-1999-1305 · Severity: high · CVSS 7.2 · Published 1994-11-30

Technologies: Sco Unix. Vendors: Sco.

Executive brief

A vulnerability exists in the 'at' utility on older SCO UNIX systems, which is a tool used to schedule tasks for future execution. A local user with basic access to the system can exploit this flaw to gain full administrative (root) control. This could allow an unauthorized person to access sensitive data, modify system files, or disrupt operations.

Technical details

A privilege escalation vulnerability exists in the 'at' executable within SCO UNIX versions 4.2 and prior. The 'at' utility, which typically runs with elevated privileges to schedule jobs for various users, contains a flaw that allows a local authenticated user to bypass security restrictions. By exploiting this vulnerability, an attacker can execute arbitrary commands with root privileges. The attack requires local shell access but no special permissions. While specific technical details like buffer overflow or race condition are not explicitly detailed in the legacy advisory, the impact is a total compromise of system confidentiality, integrity, and availability.

Affected products

  • SCO UNIX 4.2 and earlier

Timeline

  • 1994-11-30: disclosed

References

Related threats