CVE-2024-27275 - CVE House
Back to Database
Status published High CVE-2024-27275

IBM i privilege escalation

Vulnerability Description

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege can configure a physical file trigger to execute with the privileges of a user socially engineered to access the target file. The correction is to require administrator privilege to configure trigger support.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-27275

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

i
Vulnerable Versions:
7.2, 7.3, 7.4, 7.5

Timeline

Official Publish: June 15th, 2024
Last Modified: September 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)