{"api_version":"1","generated_at":"2026-07-23T09:59:44+00:00","cve":"CVE-2009-3468","urls":{"html":"https://cve.report/CVE-2009-3468","api":"https://cve.report/api/cve/CVE-2009-3468.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3468","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3468"},"summary":{"title":"CVE-2009-3468","description":"Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is enabled, allow local users to execute arbitrary commands or bypass the Mandatory Access Control (MAC) policy via unknown vectors, related to a menu typo and the Style Manager.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-09-29 19:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.9","severity":"","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-267488-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-267488-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53461","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53461","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-139620-01-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-139620-01-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-126365-15-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-126365-15-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://secunia.com/advisories/36822","name":"http://secunia.com/advisories/36822","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Sun Solaris Trusted Extensions Common Desktop Environment Vulnerability - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1022943","name":"http://www.securitytracker.com/id?1022943","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Solaris Trusted Extensions Common Desktop Environment Lets Local Users Gain Elevated Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/2756","name":"http://www.vupen.com/english/advisories/2009/2756","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/58319","name":"http://osvdb.org/58319","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/36510","name":"http://www.securityfocus.com/bid/36510","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sun Solaris Trusted Extensions Common Desktop Environment Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3468","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3468","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sun","cpe5":"solaris","cpe6":"10.0","cpe7":"*","cpe8":"sparc","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sun","cpe5":"solaris","cpe6":"10.0","cpe7":"*","cpe8":"x86","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:31:10.370Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"58319","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/58319"},{"name":"1022943","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1022943"},{"name":"36510","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36510"},{"name":"267488","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-267488-1"},{"name":"ADV-2009-2756","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/2756"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-139620-01-1"},{"name":"cde-mac-priv-escalation(53461)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53461"},{"name":"36822","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36822"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-126365-15-1"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-09-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is enabled, allow local users to execute arbitrary commands or bypass the Mandatory Access Control (MAC) policy via unknown vectors, related to a menu typo and the Style Manager."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"58319","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/58319"},{"name":"1022943","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1022943"},{"name":"36510","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36510"},{"name":"267488","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-267488-1"},{"name":"ADV-2009-2756","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/2756"},{"tags":["x_refsource_CONFIRM"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-139620-01-1"},{"name":"cde-mac-priv-escalation(53461)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53461"},{"name":"36822","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36822"},{"tags":["x_refsource_CONFIRM"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-126365-15-1"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-3468","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is enabled, allow local users to execute arbitrary commands or bypass the Mandatory Access Control (MAC) policy via unknown vectors, related to a menu typo and the Style Manager."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"58319","refsource":"OSVDB","url":"http://osvdb.org/58319"},{"name":"1022943","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1022943"},{"name":"36510","refsource":"BID","url":"http://www.securityfocus.com/bid/36510"},{"name":"267488","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-267488-1"},{"name":"ADV-2009-2756","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/2756"},{"name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-139620-01-1","refsource":"CONFIRM","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-139620-01-1"},{"name":"cde-mac-priv-escalation(53461)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53461"},{"name":"36822","refsource":"SECUNIA","url":"http://secunia.com/advisories/36822"},{"name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-126365-15-1","refsource":"CONFIRM","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-126365-15-1"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-3468","datePublished":"2009-09-29T19:00:00.000Z","dateReserved":"2009-09-29T00:00:00.000Z","dateUpdated":"2024-08-07T06:31:10.370Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-09-29 19:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*","matchCriteriaId":"7BF232A9-9E0A-481E-918D-65FC82EF36D8"},{"vulnerable":true,"criteria":"cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:*","matchCriteriaId":"0C0C3793-E011-4915-8F86-CE622A2D37D1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3468","Ordinal":"1","Title":"CVE-2009-3468","CVE":"CVE-2009-3468","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3468","Ordinal":"1","NoteData":"Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is enabled, allow local users to execute arbitrary commands or bypass the Mandatory Access Control (MAC) policy via unknown vectors, related to a menu typo and the Style Manager.","Type":"Description","Title":"CVE-2009-3468"},{"CveYear":"2009","CveId":"3468","Ordinal":"2","NoteData":"2009-09-29","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3468","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}