CVE-2005-2925

SGI IRIX - Local Command Execution via runpriv Shell Metacharacter Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-2925. PoCs published by anonymous.

AI-analyzed exploit summary This exploit leverages a command injection vulnerability in the `runpriv` utility to execute arbitrary commands with elevated privileges. It appends a new root user to `/etc/passwd` and then switches to this user to modify the passwd file further.

Description

runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · bashlocalirix
https://www.exploit-db.com/exploits/1577

This exploit leverages a command injection vulnerability in the `runpriv` utility to execute arbitrary commands with elevated privileges. It appends a new root user to `/etc/passwd` and then switches to this user to modify the passwd file further.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: runpriv (likely on Solaris or similar Unix systems)
No auth needed
Prerequisites: Access to a system with vulnerable `runpriv` utility · Ability to execute `/usr/sysadm/bin/runpriv`
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015031
Patch, Vendor Advisory third-party-advisory x_refsource_idefense
http://www.idefense.com/application/poi/display?id=312&type=vulnerabilities
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17131
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/19907
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15055
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/22561
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20051001-01-P.asc
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/427409/100/0/threaded

Scores

EPSS 0.0083
EPSS Percentile 52.6%

Details

Status published
Products (1)
sgi/irix 6.5.22
Published Oct 12, 2005
Tracked Since Feb 18, 2026