CVE-2007-4238
published 2007-08-08CVE-2007-4238: AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with bin or possibly printq privileges to gain root privileges…
PriorityP420medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.31%
23.0th percentile
AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with bin or possibly printq privileges to gain root privileges by modifying pioinit.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Incorrect Ownership Assignment
mitre_cwe·CVSS 4.6
[MEDIUM] CWE-708 Incorrect Ownership Assignment
CWE-708: Incorrect Ownership Assignment
The product assigns an owner to a resource, but the owner is outside of the intended control sphere.
This may allow the resource to be manipulated by actors outside of the intended control sphere.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Operation
Common Consequences:
Scope: Confidentiality, Integrity. Impact: Read Application Data, Modify Application Data. An attacker could read and modify data for which they do not have permissions to access directly.
Detection Methods:
Automated Analysis: Use automated tools to check for privilege settings.
Potential Mitigations:
[Policy] Periodically review the priv
CWE
Improper Isolation or Compartmentalization
mitre_cwe
CWE-653 Improper Isolation or Compartmentalization
CWE-653: Improper Isolation or Compartmentalization
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
When a weakness occurs in functionality that is accessible by lower-privileged users, then without strong boundaries, an attack might extend the scope of the damage to higher-privileged users.
Modes of Introduction:
Phase: Architecture and Design
Note: COMMISSION: This weakness refers to an incorrect design related to an architectural security tactic.
Phase: Implementation
Common Consequences:
Scope: Access Control. Impact: Gain Privileges or Assume Identity, Bypass Protection Mechanism. The exploitation of a weakness in low-privileged areas of the software can be leveraged t
http://osvdb.org/36782http://secunia.com/advisories/26219http://securitytracker.com/id?1018468http://www-1.ibm.com/support/docview.wss?uid=isg1IY79785http://www-1.ibm.com/support/docview.wss?uid=isg1IY79786http://www.vupen.com/english/advisories/2007/2678http://osvdb.org/36782http://secunia.com/advisories/26219http://securitytracker.com/id?1018468http://www-1.ibm.com/support/docview.wss?uid=isg1IY79785http://www-1.ibm.com/support/docview.wss?uid=isg1IY79786http://www.vupen.com/english/advisories/2007/2678
2007-08-08
Published