sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.
Score: 1.8
Priority: P4 - Informational (Low)
Score: 0.00642
Percentile:
0.69642
CVSS v2 Score: 10.0
Severity: