CVE-2017-3622

HIGH EXPLOITED

Oracle Sun Systems Products Suite <10 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-3622 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Metasploit, Shadow Brokers, Hacker Fantastic, bcoles, including a Metasploit module exploits/solaris/local/extremeparr_dtappgather_priv_esc.

AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in the `dtappgather` executable on Solaris systems to gain root privileges by creating a user-owned directory in `/usr/lib/locale` and loading a malicious shared object via the `LC_TIME` environment variable.

Description

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (CDE)). The supported version that is affected is 10. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. Note: CVE-2017-3622 is assigned for the "Extremeparr". CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalsolaris
https://www.exploit-db.com/exploits/45479

This Metasploit module exploits a directory traversal vulnerability in the `dtappgather` executable on Solaris systems to gain root privileges by creating a user-owned directory in `/usr/lib/locale` and loading a malicious shared object via the `LC_TIME` environment variable.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Solaris Common Desktop Environment (CDE) dtappgather (prior to Solaris 10u11)
No auth needed
Prerequisites: Access to a vulnerable Solaris system · Presence of setuid binaries like `/usr/bin/at` · GCC installed for compiling the shared object
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Shadow Brokers, Hacker Fantastic, bcoles · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/solaris/local/extremeparr_dtappgather_priv_esc.rb

This Metasploit module exploits a directory traversal vulnerability in the `dtappgather` executable on unpatched Solaris systems prior to Solaris 10u11, allowing users to gain root privileges by creating a user-owned directory at any location on the filesystem and loading a malicious shared object.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Common Desktop Environment (CDE) on Solaris systems prior to Solaris 10u11
No auth needed
Prerequisites: Access to a vulnerable Solaris system · Presence of setuid executables like `/usr/bin/at` · GCC installed for compiling the shared object
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45479/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97774
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038292

Scores

CVSS v3 7.8
EPSS 0.2147
EPSS Percentile 95.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2017-06-20
Status published
Products (2)
oracle/solaris 10
Oracle Corporation/Solaris Operating System 10
Published Apr 24, 2017
Tracked Since Feb 18, 2026