Privilege escalation in IBM DB2 - CVE-2018-1566
Published: July 7, 2018 / Updated: July 9, 2018
IBM DB2
Detailed vulnerability description
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to a flaw on systems that invoke the tool with elevated privileges. A local attacker can trigger a format string flaw in the 'db2support' tool and execute arbitrary ode with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.