CVE-2003-0579

IBM U2 UniVerse <10.0.0.9 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0579. PoCs published by kf.

AI-analyzed exploit summary This exploit leverages a vulnerability in IBM U2 UniVerse's uvadmsh program, where the -uv.install option allows arbitrary file execution. By creating a malicious executable and invoking uvadmsh with the option, an attacker can escalate privileges to root.

Description

uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.

Exploits (1)

exploitdb WORKING POC VERIFIED
by kf · textlocalunix
https://www.exploit-db.com/exploits/22912

This exploit leverages a vulnerability in IBM U2 UniVerse's uvadmsh program, where the -uv.install option allows arbitrary file execution. By creating a malicious executable and invoking uvadmsh with the option, an attacker can escalate privileges to root.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: IBM U2 UniVerse version 10.0.0.9 and likely prior versions
No auth needed
Prerequisites: uvadmsh installed setuid root · write access to /tmp directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0026.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105838948002337&w=2

Scores

EPSS 0.0088
EPSS Percentile 54.3%

Details

Status published
Products (1)
ibm/u2_universe < 10.0.0.9
Published Aug 18, 2003
Tracked Since Feb 18, 2026