Executive brief
Sun Microsystems Solstice AdminSuite, a tool used for managing Solaris systems, contains a flaw in how it handles temporary lock files. A local user on the system can exploit this behavior to gain full administrative (root) control over the machine. This could lead to a total compromise of the system's data and operations.
Technical details
A race condition or symlink vulnerability exists in Solaris Solstice AdminSuite versions 2.1 and 2.2 due to insecure lock file creation. Because these lock files are created with insufficient validation or in predictable, world-writable locations, a local attacker can manipulate the file system (e.g., via symbolic links) to intercept or redirect file operations performed by the privileged AdminSuite process. Successful exploitation allows a non-privileged local user to escalate their privileges to root. Sun Microsystems released security bulletin 145 to address this issue.
Affected products
- Sun Microsystems Solstice AdminSuite 2.1, 2.2
Timeline
- 1997-11-10: disclosed: Initial NVD publication date
- 1997-11-10: advisory: Sun Security Bulletin 145 released