Executive brief
Sun Microsystems Solstice AdminSuite, a tool used for managing users and systems in Solaris environments, contains a security flaw in how it handles user permissions. This vulnerability allows a standard user already on the system to modify their own account details in a way that grants them full administrative (root) control. This could lead to a complete takeover of the affected server and unauthorized access to all stored data.
Technical details
A privilege escalation vulnerability exists in Solaris Solstice AdminSuite 2.1 due to the application of insecure permissions when creating new user entries in the NIS+ password table. When a user is added via the AdminSuite, the resulting NIS+ table entries are created with permissions that allow the user to modify their own record. A local attacker can exploit this by altering their own entry to change their User ID (UID) to 0 or modify other sensitive fields, effectively gaining root privileges. This requires local access to the system and the presence of NIS+ for user management. Patches were historically provided by Sun Microsystems in security bulletin 145.
Affected products
- Sun Microsystems Solstice AdminSuite 2.1
Timeline
- 1997-11-10: disclosed: Initial publication date
- 1997-11-10: advisory