runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.002
                        
                    
                    
                        
                            EPSS Ranking 42.4%