CVE-2000-1028

HP-UX 11.0 - Buffer Overflow via cu Program -l Argument

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2000-1028. PoCs published by zorgon.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in HP-UX /bin/cu (CVE-2000-1028) by overwriting the return address with a shellcode payload. It uses a NOP sled and a fixed offset to achieve remote code execution.

Description

Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.

Exploits (2)

exploitdb WORKING POC VERIFIED
by zorgon · clocalhp-ux
https://www.exploit-db.com/exploits/245

This exploit targets a buffer overflow vulnerability in HP-UX /bin/cu (CVE-2000-1028) by overwriting the return address with a shellcode payload. It uses a NOP sled and a fixed offset to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP-UX /bin/cu (HP-UX 11.00)
No auth needed
Prerequisites: Access to the target system · Ability to execute /bin/cu
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by zorgon · textdoshp-ux
https://www.exploit-db.com/exploits/20373

The exploit demonstrates a buffer overflow in HP-UX's `cu` utility via the `-l` option. By providing an argument exceeding 9777 bytes, the stack is corrupted, potentially leading to arbitrary code execution with root privileges.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: HP-UX cu utility (version unspecified)
No auth needed
Prerequisites: Access to a vulnerable HP-UX system with `cu` installed setuid root
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1886
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5460
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/142792

Scores

EPSS 0.0148
EPSS Percentile 70.6%

Details

Status published
Products (11)
hp/hp-ux 9.00
hp/hp-ux 9.01
hp/hp-ux 9.04
hp/hp-ux 9.05
hp/hp-ux 9.06
hp/hp-ux 9.07
hp/hp-ux 9.08
hp/hp-ux 9.09
hp/hp-ux 9.10
hp/hp-ux 10.20
... and 1 more
Published Dec 11, 2000
Tracked Since Feb 18, 2026