Back to Database
Status published
High
CVE-2024-27134
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf
Vulnerability Description
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-27134
Credits & Attribution
No credits recorded in the NVD database.
References
More from Unknown
View All →CVE-2025-9978
Jeg Elementor Kit < 2.7.0 - Author+ Stored XSS
Unknown
0
CVE-2025-9959
Sandbox escape in smolagents Local Python execution environment via dunder attributes
High
7.6
CVE-2025-9900
Libtiff: libtiff write-what-where
High
8.8
CVE-2025-9784
Undertow: undertow madeyoureset http/2 ddos vulnerability
High
7.5
CVE-2025-9710
Responsive Lightbox & Gallery < 2.5.3 - Unauthenticated Stored-XSS via Comments
Unknown
0
Affected Vendor
Unknown
View all reports →Affected Software
Unknown
Vulnerable Versions:
0
Timeline
Official Publish:
November 25th, 2024
Last Modified:
November 25th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
MITRE ATT&CK TTPs
T1574
Hijack Execution Flow
Privilege Escalation
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1036
Masquerading
Defense Evasion
T1485
Data Destruction
Impact
T1005
Data from Local System
Collection
T1222
File and Directory Permissions Modification
Defense Evasion
T1078
Valid Accounts
Persistence
T1021
Remote Services
Lateral Movement