CVE-2019-3010 is a critical local privilege escalation vulnerability affecting Oracle Solaris 11, specifically within the XScreenSaver component. A low-privileged attacker with logon access can exploit this flaw to gain full control over the Solaris system, leading to complete compromise of confidentiality, integrity, and availability. With a CVSS v3.0 score of 8.8 (High), this vulnerability is easily exploitable with low attack complexity and no user interaction required. It is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has been linked to malware like BPFDoor.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.