CVE-2019-3010: high-severity vulnerability in Oracle Corporation Solaris Operating System
Published · Updated
91Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 8.8epss 13%
from disclosure to weapon0 days
Published on NVDOct 16
1st PoCJul 12
metasploitOct 16
CISA KEV+952d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesCISA + VulnCheck
5 public exploit(s)
Action required by CISAfederal deadline: 2022-06-15
Apply updates per vendor instructions.
In short
A flaw in XScreenSaver on Oracle Solaris 11 allows a regular user with access to the system to gain complete control over the operating system. An attacker can exploit this without user interaction, potentially compromising the entire system and any services running on it.
Technical detail
Local privilege escalation vulnerability in XScreenSaver component on Oracle Solaris 11 requiring low privileges and system logon access (AV:L/PR:L/UI:N). Successful exploitation results in complete system compromise with high confidentiality, integrity, and availability impact; scope is changed, allowing lateral impact to connected systems (CVSS 8.8).
Summary generated and translated by AI from the official description.
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).