CVE-2025-36384: IBM Db2 Privilege Escalation
IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.
Other sources
IBM Db2 for Windows could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.
— IBM
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36384?
CVE-2025-36384 is classified as a privilege escalation vulnerability affecting IBM Db2 for Windows.
How do I fix CVE-2025-36384?
To remediate CVE-2025-36384, update IBM Db2 for Windows to a version higher than 12.1.3.
Who is affected by CVE-2025-36384?
CVE-2025-36384 affects local users of IBM Db2 for Windows versions 12.1.0 to 12.1.3 with filesystem access.
What impact does CVE-2025-36384 have?
CVE-2025-36384 can allow a local user to escalate their privileges within the affected IBM Db2 environment.
Is there a workaround for CVE-2025-36384?
Currently, the recommended approach for CVE-2025-36384 is to apply the appropriate software update.