Executive brief
A vulnerability in the Utility component of Oracle Solaris allows a user with low-level access to the system to potentially gain full control over sensitive data. While difficult to exploit, a successful attack could allow an unauthorized person to view, change, or delete critical system information. This issue is particularly serious because it can impact other software running on the same server beyond just the operating system itself.
Technical details
This vulnerability exists in the Utility component of Oracle Solaris versions 11.3 and 11.4. It is classified as a local attack (AV:L) requiring low privileges (PR:L) but is characterized by high attack complexity (AC:H). The flaw involves a scope change (S:C), meaning an exploit can impact components beyond the immediate security scope of the Solaris Utility. An attacker with local logon credentials can achieve complete confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of critical system data. No user interaction is required for exploitation.
Affected products
- Oracle Solaris 11.3, 11.4
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory