peter bassill · operator
$ cve CVE-2019-3010 JSON

CVE-2019-3010 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 13.4% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-15.

Description

Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS13.4% — more likely to be exploited than 96% of all CVEs
On CISA KEVyes — remediate by 2022-06-15
Public exploityes
Published2019-10-16
Last modified2026-06-17

CISA KEV

NameOracle Solaris Privilege Escalation Vulnerability
Added2022-05-25
Due2022-06-15
Vendor / productOracle / Solaris
Ransomware usenone reported

Affected (1)

VendorProduct
oraclesolaris

Public exploits

SourceTitleDate
exploit-dbSolaris 11.4 - xscreensaver Privilege Escalation2019-10-21

References

→ the Explorer  ·  watch your stack  ·  NVD