Impact
The vulnerability allows attackers to execute arbitrary code on a Windows machine running IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13. It is caused by a configuration file that is publicly writable when the software is installed for all users, enabling the insertion of malicious configuration directives that are processed by the ACS process. This flaw is a code injection weakness (CWE‑94).
Affected Systems
IBM i Access Client Solutions versions 1.1.2.0 up to 1.1.9.13 deployed on Windows, when installed for all users.
Risk and Exploitability
The CVSS score of 7.8 signals a high‑severity flaw that could allow attackers to gain system‑level privileges. The EPSS score is not available, but the presence of a publicly writable configuration file indicates that local or privileged users could exploit the vulnerability. The issue is not listed in the CISA KEV catalog; however, environments where ACS is installed system‑wide should treat this as a serious risk and apply the fix promptly. Based on the description, the likely attack vector is an attacker with write access to the configuration file, either locally or through compromised credentials.
OpenCVE Enrichment