Executive brief
A vulnerability in the Monitor utility of the VMS operating system allows local users to gain unauthorized administrative privileges. The Monitor utility is a system tool used to track performance and system activity. An attacker with basic access to the system could exploit this flaw to take full control of the environment, potentially leading to data theft or system disruption.
Technical details
A privilege escalation vulnerability exists in the VMS Monitor utility, specifically within the SYS$SHARE:SPISHR.EXE shared image. The flaw allows a local user with standard access to execute code or manipulate system states to gain higher-level privileges. The vulnerability affects VMS versions 5.0 through 5.4-2. Successful exploitation grants the attacker full control over the operating system. Patches were historically made available by the vendor (Digital Equipment Corporation) following the initial disclosure in 1992.
Affected products
- Digital Equipment Corporation VMS 5.0 through 5.4-2
Timeline
- 1992-11-17: disclosed: Initial disclosure date recorded by NVD
- 1992-11-17: advisory: CERT advisory CA-1992-18 published