CVE-2018-2892 is a critical vulnerability within the Solaris component of Oracle Sun Systems Products Suite, specifically affecting versions 10 and 11.3. This easily exploitable local privilege escalation flaw allows a low-privileged attacker with logon access to the Solaris infrastructure to fully compromise the system, leading to complete takeover. With a CVSS 3.0 Base Score of 7.8 (High), it poses significant confidentiality, integrity, and availability risks. While not listed in CISA's KEV catalog, an exploit (EDB-45126) exists, and it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:10.0:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.