Junglewise Threat Intelligence

CVE-2019-3010: Oracle Solaris Privilege Escalation Vulnerability

CVE-2019-3010 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-25

Technologies: Oracle Solaris. Vendors: Oracle.

Executive brief

A privilege escalation vulnerability in the XScreenSaver component of Oracle Solaris 11 allows a low-privileged local attacker to compromise the operating system. Successful exploitation can lead to a complete takeover of the affected Oracle Solaris instance.

Affected products

  • Oracle Solaris 11

Timeline

  • 2019-10-16: disclosed: NVD Published Date
  • 2019-10-16: advisory: Oracle Critical Patch Update (CPU) October 2019
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-25: exploited: Reported as exploited in the wild per CISA KEV catalog entry.

Related threats