sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.
| Software | From | Fixed in |
|---|---|---|
| sas / integration_technologies | 8.0 | 8.0.x |
| sas / base | 8.0 | 8.0.x |