cbcvebase.
CVE-2010-1039
published 2010-05-20

CVE-2010-1039: Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and…

PriorityP268critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
20.17%
97.2th percentile
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
hpnfs_oncplus<= b.11.31_09
ibmaix<= 5.3
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix

Detection & IOCsextracted from sources · hover to see the quote

processrpc.pcnfsd
otherPCNFSD_PROG=150001
otherPCNFSD_VERS=1
otherPCNFSD_PR_INIT=2
otherPCNFSD_PR_START=3
commandauthunix_create("localhost", 0, 0, 0, NULL)
commandclnt_call(cl, PCNFSD_PR_START, xdr_cm_send2, ...)
  • Monitor for RPC calls targeting ONC RPC program number 150001 (PCNFSD), version 1, procedure 3 (PR_START) with malformed/format-string-containing directory name arguments.
  • Alert on RPC requests to rpc.pcnfsd (program 150001) where string arguments contain format string specifiers (e.g., %n, %x, %s) in the directory name field.
  • The exploit uses AUTH_UNIX credentials with UID/GID 0 (root) — flag unauthenticated or zero-credential RPC calls to PCNFSD program 150001.
  • Inspect RPC portmapper/rpcbind traffic for registrations or lookups of program number 150001 on affected AIX, VIOS, HP-UX, and IRIX hosts.
  • ·Affected platforms span IBM AIX 6.1/5.3 and earlier, IBM VIOS 2.1/1.5 and earlier, HP HP-UX B.11.11/B.11.23/B.11.31 with NFS/ONCplus B.11.31_09 and earlier, and SGI IRIX 6.5 — detection rules should be scoped to these OS environments.
  • ·The exploit was specifically tested against AIX 6.1.0 and lower; behaviour on other affected platforms may differ and exploit reliability is not guaranteed across all listed versions.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.