Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain a heap buffer overflow that allows a remote attacker to execute arbitrary code on the target system. The overflow can lead to full compromise of the affected platform, resulting in loss of confidentiality, integrity, and availability. The vulnerability is identified as CWE-787 and is rated high with a CVSS score of 8.8.
Affected Systems
The affected products are IBM AIX 7.2 and 7.3 release lines and IBM PowerVM VIOS 4.1. All sub‑versions in those lines are vulnerable, and IBM recommends updating to any of the following remediation levels: for AIX 7.3 TL04 Service Pack 2, AIX 7.3 TL03 Service Pack 3, AIX 7.3 TL02 Service Pack 5, AIX 7.2 TL05 Service Pack 13; for VIOS 4.1.0 Fix Pack 4.1.0.50, VIOS 4.1.1 Fix Pack 4.1.1.30, and VIOS 4.1.2 Fix Pack 4.1.2.20. These Service Packs and Fix Packs are cumulative and include all prior fixes.
Risk and Exploitability
The CVSS score of 8.8 indicates high potential impact. The EPSS score, listed as < 1%, shows a low probability of current exploitation in the wild. This vulnerability can be triggered by a remote network attacker with no special privileges, making remote exploitation plausible. It is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote, network‑based exploitation that triggers the heap overflow via externally supplied data, leading to arbitrary code execution.
OpenCVE Enrichment