VMS Monitor Vulnerability

BID:51

Info

VMS Monitor Vulnerability

Bugtraq ID: 51
Class: Unknown
CVE: CVE-1999-1395
Remote: No
Local: Yes
Published: Jul 22 1992 12:00AM
Updated: Jul 11 2009 12:16AM
Credit:
Vulnerable: Digital VMS 5.4.2
Digital VMS 5.4.1
Digital VMS 5.4
Digital VMS 5.3.2
Digital VMS 5.3.1
Digital VMS 5.3
Digital VMS 5.2.1
Digital VMS 5.2
Digital VMS 5.1.2
Digital VMS 5.1.1
Digital VMS 5.1 B
Digital VMS 5.1
Digital VMS 5.0.2
Digital VMS 5.0.1
Digital VMS 5.0
Not Vulnerable: Digital VMS 5.5.1
Digital VMS 5.5
Digital VMS 5.4.3

Discussion

VMS Monitor Vulnerability

Unauthorized privileges may be expanded to authorized
users of a system under certain conditions, via the Monitor
utility. This problem will not permit unauthorized access
entry, as individuals attempting to gain unauthorized access
will continue to be denied through the standard VMS
security mechanisms

Exploit / POC

VMS Monitor Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

Solution / Fix

VMS Monitor Vulnerability

Solution:
This potential vulnerability does not exist in VMS V5.4-3
(released in October 1991) and later versions of VMS
through V5.5-1.

Digital strongly recommends that you upgrade to a minimum
of VMS V5.4-3, and further, to the latest release of VMS
V5.5-1. (released in July, 1992)

A VMS V5.0 through V5.4-2 remedial kit is now available
by contacting your normal Digital Services Support
organization. The kit may be identified as
MONTOR$S01_05* or CSCPAT_1047 via DSIN , and
DSNlink.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report