Junglewise Threat Intelligence

CVE-1999-1312: DEC OpenVMS privilege escalation in VAX and AXP

CVE-1999-1312 · Severity: high · CVSS 7.2 · Published 1993-02-24

Executive brief

A security vulnerability in older versions of the DEC OpenVMS operating system allows a user who already has access to the system to gain full administrative control. This could lead to the unauthorized viewing of sensitive data, modification of system files, or a complete shutdown of operations. The issue affects legacy VAX and AXP systems used in various enterprise environments.

Technical details

A privilege escalation vulnerability exists in DEC OpenVMS VAX versions 5.0 through 5.5-2 and OpenVMS AXP version 1.0. The flaw allows a local user with standard access to bypass security restrictions and gain full system privileges. While the specific technical root cause (such as a buffer overflow or race condition) is not detailed in the legacy advisory, the impact is a complete compromise of confidentiality, integrity, and availability. Attackers must have local login access to the system to exploit this vulnerability. Patch information was originally distributed via CERT advisory CA-1993-05.

Affected products

  • DEC OpenVMS VAX 5.0 through 5.5-2
  • DEC OpenVMS AXP 1.0

Timeline

  • 1993-02-24: advisory: Initial NVD publication date
  • 1993-02-24: disclosed: CERT advisory CA-1993-05 released

References