LiveActive security incident?Get immediate response
CVE Record

CVE-1999-1183: System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing...

System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user's Mailcap entry supports the x-sgi-task or x-sgi-exec type.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-1999-1183 is an old SGI IRIX System Manager issue. A malicious descriptor file could cause command execution when handled through specific Mailcap file types. Business urgency is mainly for organizations still operating or emulating SGI IRIX 6.3 or 6.4, especially where users process untrusted files or mail content.

Executive priority

Prioritize only if legacy SGI IRIX systems remain in production, labs, manufacturing, or archives. For most modern environments, urgency is low because the affected platform is obsolete. For confirmed IRIX 6.3/6.4 use, treat as a legacy remote code execution risk requiring containment.

Technical view

The sysmgr GUI in SGI IRIX 6.3 and 6.4 can execute commands through trojaned runtask or runexec descriptor files when Mailcap supports x-sgi-task or x-sgi-exec. The public record provides no CVSS, CWE, patch, or structured affected-product data beyond the description.

Likely exposure

Likely limited to legacy SGI IRIX 6.3 or 6.4 systems with System Manager and relevant Mailcap handlers enabled. Exposure depends on users or workflows receiving and opening untrusted descriptor content.

Exploitation context

The source describes remote attackers providing malicious descriptor files, but does not show active exploitation. CISA KEV is not indicated. Successful exploitation appears configuration- and user/workflow-dependent through Mailcap handling.

Researcher notes

Public data is sparse. The CVE record names the vulnerable component and trigger conditions but lacks CVSS, CWE, references, patch status, and precise vendor metadata. Avoid assuming exploit availability or remediation details beyond checking vendor guidance and reducing exposure.

Mitigation direction

  • Identify and retire or isolate SGI IRIX 6.3 and 6.4 systems.
  • Check archived SGI or vendor guidance for any supported fix or configuration change.
  • Restrict handling of untrusted sysmgr descriptor files and related mail content.
  • Review Mailcap associations for x-sgi-task and x-sgi-exec on affected hosts.

Validation and detection

  • Inventory environments for SGI IRIX 6.3 and 6.4 systems.
  • Confirm whether System Manager sysmgr GUI is installed or used.
  • Review Mailcap entries for x-sgi-task and x-sgi-exec handlers.
  • Check whether users receive or open untrusted descriptor attachments or files.
  • Document compensating controls for any system that cannot be retired.
Prepared
Confidence
medium
Sources
2

Public sources used

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-1999-1183 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
1Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.