VMS 4.0-5.3 Privilege Escalation

MEDIUM (4.6) Patch Available Patch Patch

Threat Intelligence

Low Risk
EPSS Score: 0.21% chance of exploitation (percentile: 43%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

VMS 4.0 through 5.3 is a proprietary operating system used by the US Department of Energy (DOE). This vulnerability allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command, which can lead to unauthorized access and potential data breaches.

Am I affected?

You're affected if you use VMS 4.0 through 5.3. If you don't recognize the name "VMS" or its proprietary nature, you're probably not affected. Check with your system administrator or IT department if your organization uses VMS products.

Version info: Not specified in the advisory.

Affected Products

US Department of Energy / VMS

How to fix

Contact the DOE directly for a patched version - there's no public patch link in the advisory.
Immediate mitigations:
- Restrict access to sensitive commands (e.g., ANALYZE/PROCESS_DUMP)
- Monitor system logs for suspicious activity