{"id":"CVE-1999-1022","title":"serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.","summary":"serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.","severity":"medium","cvss":6.2,"cvssVector":"AV:L/AC:H/Au:N/C:C/I:C/A:C","published":"1994-10-02","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1022","references":[{"url":"http://www.securityfocus.com/archive/1/930","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/464","label":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/2111","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/archive/1/930","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/464","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/2111","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.00793,"epssPercentile":0.54389,"ingestedAt":"2026-06-19T03:39:00.742Z","exploitAvailable":true,"exploits":{"exploitdb":true,"checkedAt":"2026-09-21T15:23:18.527Z"},"slug":"CVE-1999-1022","body":"## Overview\n\nserial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":34.1,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}