CVE Vulnerabilities

CVE-2024-27273

Incorrect Privilege Assignment

Published: May 07, 2024 | Modified: Aug 18, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM AIXs Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
ViosIbm3.1 (including)3.1 (including)
ViosIbm4.1 (including)4.1 (including)
AixIbm7.2 (including)7.2 (including)
AixIbm7.3 (including)7.3 (including)

Potential Mitigations

References