Executive brief
A security vulnerability in older versions of the DEC OpenVMS operating system allows a user who already has access to the system to gain full administrative control. This could lead to the unauthorized viewing of sensitive data, modification of system files, or a complete shutdown of operations. The issue affects legacy VAX and AXP systems used in various enterprise environments.
Technical details
A privilege escalation vulnerability exists in DEC OpenVMS VAX versions 5.0 through 5.5-2 and OpenVMS AXP version 1.0. The flaw allows a local user with standard access to bypass security restrictions and gain full system privileges. While the specific technical root cause (such as a buffer overflow or race condition) is not detailed in the legacy advisory, the impact is a complete compromise of confidentiality, integrity, and availability. Attackers must have local login access to the system to exploit this vulnerability. Patch information was originally distributed via CERT advisory CA-1993-05.
Affected products
- DEC OpenVMS VAX 5.0 through 5.5-2
- DEC OpenVMS AXP 1.0
Timeline
- 1993-02-24: advisory: Initial NVD publication date
- 1993-02-24: disclosed: CERT advisory CA-1993-05 released