“Shadow Brokers” Solaris Vulnerabilities
Today we released the April Critical Patch Update. The section titled “Shadow Brokers” Solaris Vulnerabilities, containing the following important announcement.
“Shadow Brokers” Solaris Vulnerabilities
The Shadow Brokers hacking group publicly disclosed a number of exploits allegedly stolen from the United States National Security Agency. Among these disclosed vulnerabilities were two Solaris vulnerabilities for which Oracle obtained CVE identifiers: “Extremeparr” has received CVE-2017-3622, and “Ebbisland” has received CVE-2017-3623.
CVE-2017-3622 (a.k.a. “Extremeparr”) has a CVSS Base Score of 7.8, and if successfully exploited allows a local privilege escalation in the ‘dtappgather’ component. A fix for this vulnerability is provided in the April 2017 Critical Patch Update.