Impact
The vulnerability resides in a driver component of Oracle Solaris, allowing a high‑privileged local user to create, delete, or modify critical data, or gain full access to all Solaris‑accessible data. The weakness results in direct confidentiality and integrity compromise but no impact on availability. The CVSS vector indicates a local attack with low authentication complexity, requiring high privileges and human interaction from a user other than the attacker. The documented impacts are unauthorized data creation, deletion, modification, and unauthorized access to critical data.
Affected Systems
Oracle Corporation’s Solaris operating system, specifically version 11, is affected. The driver component is the precise target of the flaw and any installation of Solaris 11 within a corporate infrastructure exposes the environment to this risk.
Risk and Exploitability
The CVSS base score of 5.8 reflects moderate severity. Exploit probability per EPSS is very low, reported as less than 1%. The vulnerability is not listed in the CISA KEV catalog. Because the exploit requires a local high‑privileged foothold and user interaction with an unrelated user, the likelihood of successful attacks in the wild is limited, though the impact of success is substantial.
OpenCVE Enrichment