CVE-2008-4556

Sun Solaris 8 and 9 - Stack-Based Buffer Overflow in adm_build_path Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2008-4556. PoCs published by Metasploit, kingcope, Adriano Lima, including Metasploit module exploits/solaris/sunrpc/sadmind_adm_build_path.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the `adm_build_path()` function of the Solaris `sadmind` daemon (CVE-2008-4556). It uses a brute-force approach to bypass ASLR by targeting memory addresses in the `sadmind` process, delivering a payload to achieve remote code execution.

Description

Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotesolaris
https://www.exploit-db.com/exploits/16325

This exploit targets a buffer overflow vulnerability in the `adm_build_path()` function of the Solaris `sadmind` daemon (CVE-2008-4556). It uses a brute-force approach to bypass ASLR by targeting memory addresses in the `sadmind` process, delivering a payload to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sun Solaris sadmind (Solaris 9 x86)
No auth needed
Prerequisites: Network access to the target's sadmind service (UDP port 100232) · Target running vulnerable Solaris 9 x86
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by kingcope · perlremotesolaris
https://www.exploit-db.com/exploits/6786

This exploit targets a remote buffer overflow vulnerability in SunOS 5.9's sadmind service, allowing unauthenticated remote code execution. It uses a crafted RPC request to trigger the overflow and execute a bind shell on port 5555.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SunOS 5.9 (Solaris 9) sadmind
No auth needed
Prerequisites: Network access to the target's sadmind service (UDP port 100069 or similar)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Adriano Lima · rubyremotesolaris
https://www.exploit-db.com/exploits/9920

This exploit targets a buffer overflow vulnerability in the `adm_build_path()` function of the Solaris `sadmind` daemon (CVE-2008-4556). It uses a brute-force approach to bypass ASLR by targeting memory addresses in the `sadmind` process, delivering a payload via a maliciously crafted SunRPC request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sun Solaris sadmind (versions including Solaris 9 x86)
No auth needed
Prerequisites: Network access to the target's sadmind service (UDP port 100232) · Target running vulnerable Solaris version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
by Ramon de C Valle · rubypocsolaris
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/solaris/sunrpc/sadmind_adm_build_path.rb

This Metasploit module exploits a buffer overflow in the `adm_build_path()` function of the Sun Solstice AdminSuite `sadmind` daemon (CVE-2008-4556). It targets Sun Solaris 9 x86 systems via a crafted SunRPC request to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sun Solstice AdminSuite sadmind daemon (Solaris 9 x86)
No auth needed
Prerequisites: Network access to UDP port 100232 (sadmind) · Vulnerable Solaris 9 x86 system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (15)

Core 15
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2824
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32283
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45858
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-245806-1
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6786
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5543
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021059
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31751
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/50019
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4408
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/497311/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32812
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3230

Scores

EPSS 0.6986
EPSS Percentile 99.3%

Details

CWE
CWE-119
Status published
Products (2)
sun/solaris 8 (2 CPE variants)
sun/solaris 9 (2 CPE variants)
Published Oct 14, 2008
Tracked Since Feb 18, 2026