HIGH🇵🇱 Wersja polska

CVE-2018-1165

CVSS 7.0v3.1pub. 2018-02-21upd. 2024-11-21

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Joyent Smartos

    OS
    Joyent
    20170803
  • Oracle Solaris

    OS
    Oracle
    11
  • Oracle Zfs Storage Appliance

    OS
    Oracle
    8.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2020-14871CRITICAL10.0⚠ KEVPL ✓same product

Oracle Solaris PAM — zdalne przejęcie systemu bez uwierzytelnienia

CVE-2013-2251CRITICAL9.8⚠ KEVPL ✓same product

Apache Struts 2: RCE przez prefiks action/redirect w parametrach

CVE-2026-46978CRITICAL10.0PL ✓same product

Auth Bypass w Oracle Solaris Remote Administration Daemon (CVSS 10.0)

CVE-2025-36038CRITICAL9.0PL ✓same product

RCE w IBM WebSphere Application Server przez niebezpieczną deserializację

CVE-2021-39085CRITICAL9.8PL ✓same product

SQL Injection w IBM Sterling B2B Integrator — nieautoryzowany dostęp do bazy danych