CVE-2024-27260: IBM AIX command execution
IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.
Other sources
IBM AIX could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27260?
CVE-2024-27260 is considered a high-severity vulnerability due to its potential for arbitrary command execution by a non-privileged local user.
How do I fix CVE-2024-27260?
To fix CVE-2024-27260, update your IBM AIX or VIOS to the latest patched version provided by IBM.
Who is affected by CVE-2024-27260?
CVE-2024-27260 affects IBM AIX versions 7.2 and 7.3, as well as VIOS versions 3.1 and 4.1.
What type of exploitation is possible with CVE-2024-27260?
CVE-2024-27260 allows a non-privileged local user to exploit the invscout command to execute arbitrary commands.
When was CVE-2024-27260 disclosed?
CVE-2024-27260 was disclosed in 2024, and affected users should take immediate action to mitigate the vulnerability.