Impact
The vulnerability is caused by a time‑of‑check/time‑of‑use race condition in IBM AIX 7.2/7.3 and PowerVM VIOS 4.1. An attacker who has local access can exploit the race to cause a denial of service and compromise data integrity, as the flaw can corrupt shared data structures or leave services in an invalid state. This weakness is identified as CWE‑367.
Affected Systems
Affected systems include IBM AIX 7.2 at TL05 SP13 or earlier, all AIX 7.3 versions that have not been updated to the listed service packs (7.3 TL04 SP2, 7.3 TL03 SP3, 7.3 TL02 SP5), and IBM PowerVM VIOS 4.1.0, 4.1.1 or 4.1.2 that have not received the corresponding fix packs (4.1.0.50, 4.1.1.30, 4.1.2.20). The fixes are cumulative and can be applied on top of any earlier affected level.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. The EPSS score of 0.00119 (<1%) shows a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, implying no known active exploitation. Attack requires local access and exploits a race condition in configuration‑management code. An attacker with local privileges could lead to a denial of service and potential data integrity violations; the description indicates a denial of service, so an attacker could potentially interrupt services. Because the issue is local, mitigation is limited to applying vendor patches.
OpenCVE Enrichment