Impact
The Oracle Solaris 11.4 Utility component contains a flaw that allows an attacker who can log in to the system with low privileges to elevate their credentials and gain complete control over the operating system. Successful exploitation would give the attacker unrestricted access to data, configuration, and all system functions, impacting confidentiality, integrity, and availability. The vulnerability is based on the CWE‑269: Improper Privilege Management.
Affected Systems
The flaw affects Oracle Solaris 11.4 only. No other releases or architectures are reported to contain the issue. Systems running this version that are exposed to local logons are susceptible.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity rating. The EPSS score of less than 1% suggests that current exploitation attempts are very rare, but the vulnerability remains exploitable by a local attacker with a valid login. As the flaw is not listed in CISA's KEV catalog, there are no publicly confirmed exploit campaigns. However, since the attack requires local credentials, any environment that allows user logons is at risk, and successful exploitation would allow the attacker to fully compromise the Solaris installation.
OpenCVE Enrichment