CVE-2023-47145: IBM Db2 for Windows privilege escalation
IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402.
Other sources
IBM Db2 for Windows (includes Db2 Connect Server) could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47145?
CVE-2023-47145 is classified as a privilege escalation vulnerability in IBM Db2.
How do I fix CVE-2023-47145?
To mitigate CVE-2023-47145, apply the latest security updates provided by IBM for the affected Db2 versions.
Which versions of IBM Db2 are affected by CVE-2023-47145?
CVE-2023-47145 affects IBM Db2 for Windows versions 10.5, 11.1, and 11.5.
Can a remote attacker exploit CVE-2023-47145?
CVE-2023-47145 requires local access, meaning a remote attacker cannot exploit this vulnerability.
What type of vulnerability is CVE-2023-47145?
CVE-2023-47145 is a local privilege escalation vulnerability using the MSI repair functionality.