VMS ANALYZE/PROCESS_DUMP Vulnerability

BID:12

Info

VMS ANALYZE/PROCESS_DUMP Vulnerability

Bugtraq ID: 12
Class: Unknown
CVE:
Remote: Unknown
Local: Unknown
Published: Oct 25 1990 12:00AM
Updated: Oct 25 1990 12:00AM
Credit:
Vulnerable: Digital VMS 5.4.3
Digital VMS 5.4.2
Digital VMS 5.4.1
Digital VMS 5.4
Digital VMS 5.3.2
Digital VMS 5.3.1
Digital VMS 5.3
Digital VMS 5.2.1
Digital VMS 5.2
Digital VMS 5.1.2
Digital VMS 5.1.1
Digital VMS 5.1 B
Digital VMS 5.1
Digital VMS 5.0.2
Digital VMS 5.0.1
Digital VMS 5.0
Digital VMS 4.0
Not Vulnerable:

Discussion

VMS ANALYZE/PROCESS_DUMP Vulnerability

Non-privileged users can acquire system privileges through the ANALYZE/PROCESS_DUMP routine.

Solution / Fix

VMS ANALYZE/PROCESS_DUMP Vulnerability

Solution:
Digital recommends that the following actions be taken on every VMS system (this includes all nodes in a VAXcluster system).

After taking the following actions, non-privileged users will not be able to use the ANALYZE/PROCESS_DUMP command.

1. Log into the system account.

2. $ SET PROC/PRIV=ALL

3. a) For VMS versions prior to V5.0,

Modify SYS$MANAGER:SYSTARTUP.COM to include the following lines:

$ SET NOON
$ MCR INSTALL ANALIMDMP.EXE/DELETE

as the first two commands in this file.

b) For VMS versions V5.0 and later,

Modify SYS$MANAGER:SYSTARTUP_V5.COM to include the following
lines:

$ SET NOON
$ MCR INSTALL ANALIMDMP.EXE/DELETE

as the first two commands in this file.

c) For MicroVMS systems,

The image ANALIMDMP.EXE is not installed by default, but
SYSTARTUP.COM contains a suggestion for installing the image if
you have multiple users on your system. You must ensure that
this image is not installed by SYSTARTUP.COM. You can use the
following command to verify that the image is not installed:

$ MCR INSTALL ANALIMDMP/LIST

4. $ MCR INSTALL ANALIMDMP/DELETE

This command removes the installed image from the active system.

5. (Optional) Restart your systems and verify that the image is not
installed using the following command:

$ MCR INSTALL ANALIMDMP/LIST

You should receive a message similar to the following:

%INSTALL-W-FAIL, failed to LIST entry for ANALIMDMP.EXE
-INSTALL-E-NOKFEFND, Known File Entry not found

References

VMS ANALYZE/PROCESS_DUMP Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report