Lucene search

K
nvd[email protected]NVD:CVE-2022-43752
HistoryOct 31, 2022 - 9:15 p.m.

CVE-2022-43752

2022-10-3121:15:13
CWE-120
web.nvd.nist.gov
1
oracle solaris
privilege escalation
common desktop environment
crafted printer
vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.8%

Oracle Solaris version 10 1/13, when using the Common Desktop Environment (CDE), is vulnerable to a privilege escalation vulnerability. A low privileged user can escalate to root by crafting a malicious printer and double clicking on the the crafted printer’s icon.

Affected configurations

Nvd
Node
oraclesolarisMatch10
AND
common_desktop_environment_project_common_desktop_environmentMatch-
VendorProductVersionCPE
oraclesolaris10cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
common_desktop_environment_project_common_desktop_environment-cpe:2.3:a:common_desktop_environment_project:_common_desktop_environment:-:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.8%

Related for NVD:CVE-2022-43752