CVE Vulnerabilities

CVE-2024-27273

Incorrect Privilege Assignment

Published: May 07, 2024 | Modified: Aug 18, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM AIXs Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Vios Ibm 3.1 (including) 3.1 (including)
Vios Ibm 4.1 (including) 4.1 (including)
Aix Ibm 7.2 (including) 7.2 (including)
Aix Ibm 7.3 (including) 7.3 (including)

Potential Mitigations

References