Vulnerability record · CVE-2019-3010 · published 16 October 2019
CVE-2019-3010: Oracle Solaris XScreenSaver local privilege escalation
Oracle · Solaris
A flaw in the XScreenSaver component of Oracle Solaris 11 allows a low-privileged user with a local logon to escalate privileges and take over the system. It matters because the affected component is present on default Solaris installations and the flaw is trivially reachable by any local account holder.
Description
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
high priorityConfirmed KEV entry with public exploit code and a high CVSS score, though exploitation requires an existing local account rather than remote access.
What it is
A flaw in the XScreenSaver component of Oracle Solaris 11 allows a low-privileged user with a local logon to escalate privileges and take over the system. It matters because the affected component is present on default Solaris installations and the flaw is trivially reachable by any local account holder.
Impact
An attacker with a local account gains full control of the Solaris host, with high confidentiality, integrity and availability impact, and the scope change means other products reachable from that host can also be affected.
Attack surface
Reached locally: the CVSS vector is AV:L with PR:L and UI:N, so the attacker needs a valid logon on the Solaris system but no user interaction and no network access.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-05-25, and public exploit code is referenced (Packet Storm), so exploitation is confirmed in the wild; EPSS 30-day probability is about 13.4 percent (96th percentile).
What to do
- Apply the Oracle October 2019 Critical Patch Update for Solaris 11 (or later) as the primary fix.
- If patching is delayed, restrict local logon and interactive access to trusted users only.
- Audit and remove unnecessary local accounts and shared credentials on Solaris hosts.
- Monitor for unexpected privilege changes or root-level activity originating from XScreenSaver processes.
Detection
- Alert on XScreenSaver process activity that spawns shells or writes to privileged paths.
- Monitor for local privilege escalation patterns such as unexpected setuid execution or new root sessions from non-admin accounts.
- Review Solaris audit logs for suspicious logon and su/sudo activity correlated with XScreenSaver.
- Track patch state of Solaris 11 hosts against the October 2019 CPU baseline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-3010 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Oracle Solaris Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/154960/Solaris-xscreensaver-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/Oct/39 | Mailing ListThird Party Advisory |
| http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html | PatchVendor Advisory |
| http://packetstormsecurity.com/files/154960/Solaris-xscreensaver-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/Oct/39 | Mailing ListThird Party Advisory |
| http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-3010 | US Government Resource |
Track CVE-2019-3010 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-3010), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.