CVE-2001-1080 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 6% (pctl 93)
Patch early
A public exploit exists.
Description
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 5.95% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-06-19 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | aix |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | AIX 4.3/5.1 - diagrpt Arbitrary Privileged Program Execution | 2003-05-23 |
References
- http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2001.225.1/%24file/oar225.txt
- http://www.securityfocus.com/bid/2916
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6734
- http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2001.225.1/%24file/oar225.txt
- http://www.securityfocus.com/bid/2916
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6734
→ the Explorer · watch your stack · NVD