CVE-2025-71263
In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size of 100 bytes. A local user can exploit this to gain root privileges. It is unlikely that UNIX v4 is running anywhere outside of a very small number of lab environments. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation95 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 %
Buffer overflow local (AV:L, PR:L) sin interacción permite escalada a root. CVSS ALTO con C:H, I:H, A:H confirma ejecución con máximos privilegios.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-120
Referencias
- https://discuss.systems/@ricci/115747843169814700
- https://sigma-star.at/blog/2025/12/unix-v4-buffer-overflow/
- https://www.spinellis.gr/blog/20251223/
- https://www.tuhs.org/pipermail/tuhs/2026-January/032991.html
- http://www.openwall.com/lists/oss-security/2026/03/20/6
- http://www.openwall.com/lists/oss-security/2026/03/21/4
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-71263",
"cveTags": [
{
"tags": [
"unsupported-when-assigned"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-71263",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-03-13T19:36:07.731823Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.4,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.4
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "AT&T Bell Labs",
"product": "UNIX",
"versions": [
{
"status": "affected",
"version": "4",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-03-13T19:53:53.983",
"references": [
{
"url": "https://discuss.systems/@ricci/115747843169814700",
"tags": [
"Issue Tracking"
],
"source": "cve@mitre.org"
},
{
"url": "https://sigma-star.at/blog/2025/12/unix-v4-buffer-overflow/",
"tags": [
"Press/Media Coverage"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.spinellis.gr/blog/20251223/",
"tags": [
"Technical Description"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.tuhs.org/pipermail/tuhs/2026-January/032991.html",
"tags": [
"Issue Tracking",
"Mailing List"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/03/20/6",
"tags": [
"Issue Tracking",
"Mailing List"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/03/21/4",
"tags": [
"Issue Tracking",
"Mailing List"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size of 100 bytes. A local user can exploit this to gain root privileges. It is unlikely that UNIX v4 is running anywhere outside of a very small number of lab environments. NOTE: This vulnerability only affects products that are no longer supported by the maintainer."
},
{
"lang": "es",
"value": "En UNIX Cuarta Edición de Investigación (v4), el comando su es vulnerable a un desbordamiento de búfer debido a que la variable 'password' tiene un tamaño fijo de 100 bytes. Un usuario local puede explotar esto para obtener privilegios de root. Es poco probable que UNIX v4 se esté ejecutando en algún lugar fuera de un número muy reducido de entornos de laboratorio."
}
],
"lastModified": "2026-06-17T10:03:58.307",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:opengroup:unix:4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AD46ACF-618C-4801-AA04-C3CBCDF854D0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}