Privilege Escalation in NeXT NeXTstep by NeXT Software
CVE-1999-1193

Currently unrated

Key Information:

Vendor

Next

Status
Vendor
CVE Published:
14 May 1991

What is CVE-1999-1193?

In NeXT NeXTstep 2.1 and earlier, the 'me' user is granted wheel group privileges that potentially enable it to execute the 'su' command, resulting in unauthorized access to root-level capabilities. This vulnerability may allow an attacker with access to the 'me' user account to escalate their privileges and gain administrative control over the system.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.