Impact
The vulnerability resides in the Utility component of Oracle Solaris, allowing a local attacker with limited privileges to gain higher privileges and modify, delete or create critical data. This affects confidentiality and integrity, enabling unauthorized access to all data accessible by the Solaris instance and potentially compromising the entire system’s data assets. This issue stems from improper access control (CWE-284). The misuse of these controls could allow the attacker to affect additional applications on the same host, potentially widening the scope of compromise.
Affected Systems
The affected products are Oracle Solaris 11.3 and Oracle Solaris 11.4, as identified by the vendor and documented in the CPE entries. No other versions are reported as affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity. The flaw requires local access, has high attack complexity, low privilege, and no user interface. The EPSS score of less than 1% shows a very low likelihood of exploitation in practice, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw enables modification of system files, an attacker could potentially pivot to other services, thereby extending the scope beyond Solaris. Exploitation requires a logged‑on user on the same infrastructure and can lead to unauthorized data modification, loss of integrity, or further privilege escalation.
OpenCVE Enrichment