Impact
IBM i 7.6, 7.5, 7.4, and 7.3 are vulnerable to improper management of thread authority swaps, allowing a local attacker to gain elevated privileges. This flaw enables an attacker who can run code on the system to execute commands with increased authority, potentially compromising all data and system integrity that the elevated user can access, including the ability to read, modify, or delete critical files and services. The weakness is defined as CWE‑269, indicating an authorization flaw that primarily results in unauthorized privilege escalation.
Affected Systems
The affected products are IBM i releases 7.3, 7.4, 7.5 and 7.6. Recommended patches include PTFs SJ10874 and SJ11023 for 7.6, SJ10875 and SJ11024 for 7.5, SJ10876 and SJ11025 for 7.4, and SJ10877 and SJ11026 for 7.3. Users running unsupported or older releases should upgrade to a supported and fixed version of IBM i as advised by IBM.
Risk and Exploitability
With a CVSS score of 8.8, this vulnerability is considered high severity; it requires local access, and no remote exploit path is documented. EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The risk of exploitation is significant for systems with local users who have the ability to run code, such as administrators or users with shared access. The CVE description explicitly indicates that improper authority swaps can result in privilege escalation, a critical security impact.
OpenCVE Enrichment