Impact
IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 contain a flaw that permits arbitrary code execution on Windows when the software is installed for all users. The installation process places a directory that is publicly writable into a location where the client automatically loads executables. By placing a malicious executable into that folder, an attacker can cause the client to run the file with the privileges of the user who installed the software, potentially enabling elevated actions if the installation runs under an administrator account. The weakness is classified as CWE‑426, an untrusted search path vulnerability.
Affected Systems
The vulnerability affects IBM i Access Client Solutions for Windows, specifically releases from version 1.1.2.0 up to and including 1.1.9.13, when the application is installed with the all‑users option. Installations that are per‑user do not expose this issue.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity level. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: an attacker who can create a file in the publicly writable ACS directory will trigger execution automatically by the client. If the application runs under elevated privileges, the consequences become even more severe, potentially granting full control of the affected machine.
OpenCVE Enrichment