CVE-2024-51459
Published: 19 March 2025
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
IBM InfoSphere Information Server 11.7 is affected by CVE-2024-51459, a vulnerability stemming from improper handling of permissions (CWE-280). This flaw enables a local user to execute privileged commands. The issue carries a CVSS v3.1 base score of 8.4 (AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant impact on confidentiality, integrity, and availability.
A local attacker requires only local access to the system, with no privileges (PR:N), low attack complexity, and no user interaction needed. Successful exploitation allows the execution of privileged commands, granting high-level control over the affected system and potentially leading to full compromise.
IBM has issued an advisory at https://www.ibm.com/support/pages/node/7185056, which provides details on the vulnerability and recommended mitigation steps, including applying available patches.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Local privilege escalation via improper permissions handling (CWE-280) enabling execution of privileged commands with no initial privileges.