VYPR
High severity8.4NVD Advisory· Published Jul 10, 2023· Updated Jun 17, 2026

CVE-2023-27558

CVE-2023-27558

Description

IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executable file in the path of the affected service. IBM X-Force ID: 249194.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • IBM/Db24 versions
    cpe:2.3:a:ibm:db2:10.5.0.11:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:ibm:db2:10.5.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:11.1.4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:11.5:*:*:*:*:-:*:*
    • (no CPE)range: 10.5, 11.1, and 11.5
  • Range: 10.5, 11.1 ,11.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.