CVE-2010-1183

Oracle Solaris - Arbitrary File Write via Symlink Attack on /tmp/CLEANUP

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2010-1183. PoCs published by Larry W. Cashdollar, Larry Cashdollar.

AI-analyzed exploit summary This exploit leverages a symbolic-link attack in Sun Connection Update Manager for Solaris to overwrite arbitrary files, leading to privilege escalation. It compiles a setuid root shell and waits for the vulnerable process to execute it during patching.

Description

Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Larry W. Cashdollar · bashlocalsolaris
https://www.exploit-db.com/exploits/33799

This exploit leverages a symbolic-link attack in Sun Connection Update Manager for Solaris to overwrite arbitrary files, leading to privilege escalation. It compiles a setuid root shell and waits for the vulnerable process to execute it during patching.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Sun Connection Update Manager for Solaris (unknown versions)
No auth needed
Prerequisites: local access · gcc installed · vulnerable Sun Connection Update Manager
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Larry W. Cashdollar · textlocallinux_x86
https://www.exploit-db.com/exploits/26709

This exploit leverages a local privilege escalation vulnerability in Solaris Recommended Patch Cluster 6/19 on x86 systems. It abuses a script execution flaw in the patch installation process to execute arbitrary commands as root by writing to /tmp/diskette_rc.d/rcs9.sh.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Solaris Recommended Patch Cluster 6/19 (x86)
Auth required
Prerequisites: Local user access on a vulnerable Solaris x86 system · Patch installation process must be triggered by an administrator
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Larry Cashdollar · textlocalsolaris
https://www.exploit-db.com/exploits/20418

This exploit targets a race condition in Solaris 10 Patch 137097-01 by symlinking a predictable file path to /etc/passwd, allowing local privilege escalation. The script monitors for the 'inetd-upgrade' process and creates a symlink to overwrite the passwd file.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Solaris 10 Patch 137097-01
Auth required
Prerequisites: Local access to the target system · Presence of the vulnerable 'inetd-upgrade' process
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/510311/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38928
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/57149
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/510305/100/0/threaded

Scores

EPSS 0.0021
EPSS Percentile 44.0%

Details

CWE
CWE-59
Status published
Products (1)
sun/solaris
Published Mar 29, 2010
Tracked Since Feb 18, 2026