Impact
This vulnerability enables a local attacker to bypass proper privilege boundaries on IBM AIX 7.2, AIX 7.3, and IBM PowerVM VIOS 4.1, allowing the attacker to achieve elevated privileges. The flaw is classified as CWE‑269, reflecting a weakness in privilege validation and enforcement. An attacker who can log on locally could gain administrative control, potentially compromising confidentiality, integrity, and availability of the affected systems.
Affected Systems
IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS 4.1 are affected. For AIX, the relevant remediation levels are SP2 for AIX 7.3 TL04, SP3 for AIX 7.3 TL03, SP5 for AIX 7.3 TL02, and SP13 for AIX 7.2 TL05. For PowerVM VIOS, the corresponding fix packs are 4.1.2.20 for VIOS 4.1.2, 4.1.1.30 for VIOS 4.1.1, and 4.1.0.50 for VIOS 4.1.0. These service packs and fix packs are cumulative and can be applied on top of earlier affected levels of the release train.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. The EPSS score of < 1% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but that absence does not reduce the impact to affected systems. The attack vector is local, requiring the attacker to be already present on the host. Successful exploitation grants full control of the system; remediation requires LPAR reboot, though AIX Live Update can eliminate downtime. Mitigation is available but must be applied promptly to prevent compromise.
OpenCVE Enrichment