Impact
This vulnerability arises from a protection mechanism failure in LLM Scaler software running in Ring 3, allowing an unprivileged local attacker to elevate privileges. The flaw is categorized as CWE‑693, improper control of a critical mechanism, and can compromise confidentiality, integrity, and availability of the target system by granting the attacker elevated rights.
Affected Systems
The affected product is LLM Scaler software. No specific vendor or version information is provided, and the software appears to be applicable to all installations running in user space. Until a vendor patch is available, any instance of LLM Scaler may be vulnerable.
Risk and Exploitability
The CVSS score is 5.4, indicating medium severity, while the EPSS score is below 1%, suggesting a low probability of exploitation. The vulnerability can be triggered locally with low complexity and requires only passive user interaction, but it is not listed in the CISA KEV catalog. If exploited, an attacker could gain elevated privileges, potentially leading to full control over the affected system.
OpenCVE Enrichment