Vulnerability record · CVE-1999-0209 · published 14 August 1990
CVE-1999-0209: SunView selection_svc allows remote file reading
Sun · Sunos
The SunView (SunTools) selection_svc facility in SunOS permits remote users to read files. This is an information disclosure flaw in a legacy Sun windowing service. Because the service is reachable over the network without authentication, exposed systems can leak file contents to anyone who can reach the port.
Description
The SunView (SunTools) selection_svc facility allows remote users to read files.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityNetwork-reachable, unauthenticated information disclosure with a high EPSS percentile, though the record is old and lacks exploit confirmation.
What it is
The SunView (SunTools) selection_svc facility in SunOS permits remote users to read files. This is an information disclosure flaw in a legacy Sun windowing service. Because the service is reachable over the network without authentication, exposed systems can leak file contents to anyone who can reach the port.
Impact
An attacker gains read access to files on the host, potentially exposing sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network (AV:N) with low complexity and no authentication required (Au:N). No user interaction is indicated by the vector or description.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is high at 0.4853 (98.8th percentile), indicating elevated predicted exploitation activity.
What to do
- Patch or upgrade SunOS to a version where the selection_svc issue is fixed; if no fix is available, retire or isolate the affected system.
- Disable the SunView/SunTools selection_svc service if it is not required.
- Block network access to the selection_svc port at the host and network firewall.
- Segment legacy SunOS hosts so they cannot be reached from untrusted networks.
- Monitor for and decommission end-of-life SunOS systems that cannot be patched.
Detection
- Monitor network traffic to the selection_svc port for unexpected remote connections.
- Audit SunOS hosts for the selection_svc process and confirm whether it is running.
- Review host logs for file access patterns consistent with remote reads via the service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-1999-0209 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-1999-0209), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.