LiveActive security incident?Get immediate response
CVE Record

CVE-1999-1114: Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating...

Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-1999-1114 is a local privilege escalation flaw in the Korn Shell suid_exec program. On affected IRIX 6.x and earlier systems, a local user may be able to gain root privileges. The main business concern is legacy UNIX systems where local accounts, shared access, or compromised low-privilege users exist.

Executive priority

Prioritize if your organization still operates IRIX or other legacy UNIX systems with local users. This is not an internet-facing remote issue based on supplied evidence, but root privilege escalation on unsupported systems can materially worsen any initial compromise.

Technical view

The CVE describes a buffer overflow in ksh suid_exec affecting IRIX 6.x and earlier, and possibly other operating systems. The stated impact is root privilege escalation by local users. Public source details are limited; no CVSS, CWE, patch version, or confirmed affected non-IRIX platforms are provided in the supplied sources.

Likely exposure

Exposure is most likely in legacy SGI IRIX environments running IRIX 6.x or earlier with Korn Shell suid_exec present. The CVE also says other operating systems are possible, but the supplied sources do not confirm specific products or versions beyond IRIX.

Exploitation context

The vulnerability requires local user access according to the CVE description. The supplied sources do not indicate remote exploitation or active exploitation, and the CVE is not listed as KEV in the provided bundle.

Researcher notes

Public details are sparse and old. The CVE names IRIX 6.x and earlier, with possible other operating systems not confirmed in the supplied sources. Avoid assuming modern ksh exposure without vendor evidence. No exploit status, patch identifier, or CVSS score is provided.

Mitigation direction

  • Inventory IRIX 6.x and earlier systems and identify ksh suid_exec presence.
  • Check SGI or platform vendor guidance for historical patches or workarounds.
  • Restrict local shell access on affected legacy systems.
  • Retire or isolate unsupported IRIX hosts where remediation is unavailable.

Validation and detection

  • Confirm operating system version on legacy UNIX assets.
  • Verify whether Korn Shell suid_exec exists and is setuid-enabled.
  • Review vendor advisories or maintenance records for applied fixes.
  • Check access controls for local user accounts on affected hosts.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-1999-1114 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.