CVE-2019-3010 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 13.4% (pctl 96)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-15.
Description
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 13.4% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | yes — remediate by 2022-06-15 |
| Public exploit | yes |
| Published | 2019-10-16 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Oracle Solaris Privilege Escalation Vulnerability |
|---|---|
| Added | 2022-05-25 |
| Due | 2022-06-15 |
| Vendor / product | Oracle / Solaris |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| oracle | solaris |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Solaris 11.4 - xscreensaver Privilege Escalation | 2019-10-21 |
References
- http://packetstormsecurity.com/files/154960/Solaris-xscreensaver-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2019/Oct/39
- http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- http://packetstormsecurity.com/files/154960/Solaris-xscreensaver-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2019/Oct/39
- http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-3010
→ the Explorer · watch your stack · NVD