← Vulnerability feed

Vulnerability record · CVE-2019-3010 · published 16 October 2019

CVE-2019-3010: Oracle Solaris XScreenSaver local privilege escalation

Oracle · Solaris

A flaw in the XScreenSaver component of Oracle Solaris 11 allows a low-privileged user with a local logon to escalate privileges and take over the system. It matters because the affected component is present on default Solaris installations and the flaw is trivially reachable by any local account holder.

8.8 CVSS 3.1 High CISA KEV since 25 May 2022 EPSS 13% · top 3.7%
8.8CVSS 3.1 base score, v2 4.6
13%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityConfirmed KEV entry with public exploit code and a high CVSS score, though exploitation requires an existing local account rather than remote access.

What it is

A flaw in the XScreenSaver component of Oracle Solaris 11 allows a low-privileged user with a local logon to escalate privileges and take over the system. It matters because the affected component is present on default Solaris installations and the flaw is trivially reachable by any local account holder.

Impact

An attacker with a local account gains full control of the Solaris host, with high confidentiality, integrity and availability impact, and the scope change means other products reachable from that host can also be affected.

Attack surface

Reached locally: the CVSS vector is AV:L with PR:L and UI:N, so the attacker needs a valid logon on the Solaris system but no user interaction and no network access.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2022-05-25, and public exploit code is referenced (Packet Storm), so exploitation is confirmed in the wild; EPSS 30-day probability is about 13.4 percent (96th percentile).

What to do

  • Apply the Oracle October 2019 Critical Patch Update for Solaris 11 (or later) as the primary fix.
  • If patching is delayed, restrict local logon and interactive access to trusted users only.
  • Audit and remove unnecessary local accounts and shared credentials on Solaris hosts.
  • Monitor for unexpected privilege changes or root-level activity originating from XScreenSaver processes.

Detection

  • Alert on XScreenSaver process activity that spawns shells or writes to privileged paths.
  • Monitor for local privilege escalation patterns such as unexpected setuid execution or new root sessions from non-admin accounts.
  • Review Solaris audit logs for suspicious logon and su/sudo activity correlated with XScreenSaver.
  • Track patch state of Solaris 11 hosts against the October 2019 CPU baseline.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-3010 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Oracle Solaris Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3010 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-14871Oracle Solaris PAM out-of-bounds write allows remote unauthenticated takeoverOracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network withou…KEVEPSS 80%analysed8.8CVE-2015-4495Firefox PDF reader same-origin bypass allows file read and privilege gainThe PDF reader in Mozilla Firefox (before 39.0.3), Firefox ESR 38.x (before 38.1.1), and Firefox OS (before 2.2) fails to properly validate origin, l…KEVEPSS 69%analysed7.8CVE-2008-2992Adobe Acrobat and Reader util.printf Stack Buffer OverflowAdobe Acrobat and Reader 8.1.2 and earlier contain a stack-based buffer overflow reachable through the util.printf JavaScript function when it is pas…KEVEPSS 98%analysed5.5CVE-2016-3718ImageMagick HTTP/FTP coders allow server-side request forgery via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. A…KEVEPSS 77%analysed5.5CVE-2016-3715ImageMagick EPHEMERAL coder allows arbitrary file deletionThe EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 lets a crafted image cause deletion of arbitrary files. This is part of the…KEVEPSS 75%analysed10.0CVE-2026-46978Oracle solaris improper access control vulnerabilityVulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11…EPSS 0.43%10.0CVE-2017-3623Oracle solaris vulnerabilityVulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see …EPSS 22%10.0CVE-2015-8104Xen vulnerabilityThe KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic o…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2019-3010), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.