CVE-1999-0064

IBM AIX - Buffer Overflow in lquerylv Program

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-1999-0064. PoCs published by Georgi Guninski, HORKimhab.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the `lquerylv` program, leveraging shellcode to execute `/bin/sh`. It manipulates environment variables to trigger the overflow and achieve remote code execution.

Description

Buffer overflow in AIX lquerylv program gives root access to local users.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Georgi Guninski · clocalaix
https://www.exploit-db.com/exploits/335

This exploit targets a buffer overflow vulnerability in the `lquerylv` program, leveraging shellcode to execute `/bin/sh`. It manipulates environment variables to trigger the overflow and achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: lquerylv (version unspecified, likely older AIX or Linux systems)
No auth needed
Prerequisites: Presence of vulnerable `lquerylv` binary · Ability to execute the binary with crafted environment variables
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
github STUB
by HORKimhab · shellpoc
https://github.com/HORKimhab/poc-cve-collection/tree/main/1999/0xxx/CVE-1999-0064.md

The repository contains only a markdown file with a brief description of CVE-1999-0064, a buffer overflow in AIX's lquerylv program that allows local privilege escalation. No functional exploit code or technical details are provided.

Classification
Stub 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: AIX lquerylv program (unspecified version)
Auth required
Prerequisites: local access to a vulnerable AIX system
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

EPSS 0.0075
EPSS Percentile 51.2%

Details

Status published
Products (10)
ibm/aix 3.2
ibm/aix 3.2.4
ibm/aix 3.2.5
ibm/aix 4.1
ibm/aix 4.1.1
ibm/aix 4.1.2
ibm/aix 4.1.3
ibm/aix 4.1.4
ibm/aix 4.1.5
ibm/aix 4.2
Published May 26, 1997
Tracked Since Feb 18, 2026