ZeroHour

CVE-2019-3010

KEV PoC large

Local Privilege Escalation in Oracle Solaris 11 XScreenSaver

CISA: Oracle Solaris Privilege Escalation Vulnerability

CVSS 3.1
8.8 high
EPSS
13%p96
Published
()
KEV added
AI analysis

CVE-2019-3010 is a local privilege escalation flaw in the XScreenSaver component of Oracle Solaris 11, rated 8.8 (High) with the scope-change flag set, meaning the compromise of the component can extend beyond it to the rest of the host. A low-privileged attacker who can log on to the system can trigger the vulnerability with no user interaction or complex preconditions, gaining full takeover of the Solaris host with high confidentiality, integrity, and availability impact. Because of the scope change, Oracle notes that successful attacks may also significantly impact additional products running on the infrastructure. Only Oracle Solaris 11 is listed as affected. A public proof-of-concept exploit has been available since 2019, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25, indicating known exploitation in the wild; ransomware use is unknown.

What to do: Apply the Oracle Solaris 11 security updates per vendor instructions, as required by the CISA KEV catalog entry (added 2022-05-25). Inventory all Solaris 11 hosts—especially those exposing SSH or other logon access to low-privileged users—and prioritize patching internet-reachable or multi-tenant systems. Monitor EPSS (13.4% probability of exploitation within 30 days, 96th percentile) and restrict local accounts on Solaris hosts until patches are applied.

Affected
Oracle Solaris (XScreenSaver component)Oracle Solaris 11
Estimated exposure
largetens of thousands of Solaris 11 systems, likely 10k-100k hosts in enterprise, government, and telecom data centers (exact install base not published) — Solaris 11 has been Oracle's flagship enterprise Unix for over a decade with a substantial long-lived installed base on SPARC and x86 servers, though it requires local logon to exploit, so only systems granting low-privileged shell access…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CISA Known Exploited Vulnerability
Affected
Oracle Solaris
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
solaris
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.