Vulnerabilities > CVE-2004-1329 - Local Privilege Escalation vulnerability in IBM AIX Diag

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
ibm
exploit available

Summary

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.

Vulnerable Configurations

Part Description Count
OS
Ibm
7

Exploit-Db

  • descriptionIBM AIX 5.x Diag Local Privilege Escalation Vulnerabilities. CVE-2004-1329. Local exploit for aix platform
    idEDB-ID:25039
    last seen2016-02-03
    modified2004-12-20
    published2004-12-20
    reportercees-bart
    sourcehttps://www.exploit-db.com/download/25039/
    titleIBM AIX 5.x - Diag Local Privilege Escalation Vulnerabilities
  • idEDB-ID:701