runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 52.7%