Impact
The vulnerability is a local privilege escalation flaw that allows an already authenticated user to gain root access on systems running Fujitsu Linux openFT or Fujitsu Oracle Solaris openFT. It is a CWE-269 type weakness related to inappropriate use of privileged accounts. Successful exploitation would enable the actor to read or modify any file, install malicious software, or otherwise subvert the system’s security.
Affected Systems
This flaw affects Fujitsu Linux openFT and Fujitsu Oracle Solaris openFT versions before 12.1D00 on GNU/Linux and Oracle Solaris systems. End users running these older products are at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates a high-severity local exploit. The EPSS score is < 1%, suggesting a very low but non-zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires that the attacker already has local authentication, the likely attack vector is local and requires legitimate access to the system. Once authenticated, the attacker can elevate to root without additional steps.
OpenCVE Enrichment