CVE-2005-1394

ArcGIS for ESRI ArcInfo Workstation 9.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1394. PoCs published by Kevin Finisterre.

AI-analyzed exploit summary This exploit leverages a format string vulnerability in ESRI ArcGIS 9.x's wservice binary to overwrite the thr_jmp_table and achieve local privilege escalation on Solaris 10. It uses a carefully crafted environment variable to trigger the vulnerability and execute shellcode that spawns a root shell.

Description

Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kevin Finisterre · clocalsolaris
https://www.exploit-db.com/exploits/972

This exploit leverages a format string vulnerability in ESRI ArcGIS 9.x's wservice binary to overwrite the thr_jmp_table and achieve local privilege escalation on Solaris 10. It uses a carefully crafted environment variable to trigger the vulnerability and execute shellcode that spawns a root shell.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: ESRI ArcGIS 9.x (wservice binary)
No auth needed
Prerequisites: Local access to the target system · Presence of vulnerable ESRI ArcGIS 9.x installation · Solaris 10 environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=111489411524630&w=2
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15196
Patch, Third Party Advisory x_refsource_misc
http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt
Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013852

Scores

EPSS 0.0083
EPSS Percentile 52.7%

Details

CWE
CWE-134
Status published
Products (1)
esri/arcinfo_workstation 9.0
Published May 03, 2005
Tracked Since Feb 18, 2026