Junglewise Threat Intelligence

CVE-1999-1424: Sun Solaris Solstice AdminSuite privilege escalation in NIS+ password table

CVE-1999-1424 · Severity: medium · CVSS 6.2 · Published 1997-11-10

Vendors: Sun Microsystems.

Executive brief

Sun Microsystems Solstice AdminSuite, a tool used for managing users and systems in Solaris environments, contains a security flaw in how it handles user permissions. This vulnerability allows a standard user already on the system to modify their own account details in a way that grants them full administrative (root) control. This could lead to a complete takeover of the affected server and unauthorized access to all stored data.

Technical details

A privilege escalation vulnerability exists in Solaris Solstice AdminSuite 2.1 due to the application of insecure permissions when creating new user entries in the NIS+ password table. When a user is added via the AdminSuite, the resulting NIS+ table entries are created with permissions that allow the user to modify their own record. A local attacker can exploit this by altering their own entry to change their User ID (UID) to 0 or modify other sensitive fields, effectively gaining root privileges. This requires local access to the system and the presence of NIS+ for user management. Patches were historically provided by Sun Microsystems in security bulletin 145.

Affected products

  • Sun Microsystems Solstice AdminSuite 2.1

Timeline

  • 1997-11-10: disclosed: Initial publication date
  • 1997-11-10: advisory

References