Impact
A vulnerability exists in the Oracle Solaris Filesystems component that can be exploited by a low‑privileged user who can log onto the system. The flaw allows the attacker to compromise Oracle Solaris entirely, leading to full loss of confidentiality, integrity and availability for the affected machine. The weakness is an improper access control over filesystem operations, making the system susceptible to takeover by users with local logon rights.
Affected Systems
Oracle Solaris 11.4 is affected. The vulnerability resides in the Filesystems component of this version. No other versions or product families are mentioned as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 indicates a high‑severity issue. Exploitation requires only local logon, and the description notes that the attack is difficult to conduct, which is reflected in an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog. The likely attack path is a local attacker leveraging login credentials to execute privileged filesystem commands and gain control of the operating system.
OpenCVE Enrichment