Impact
The vulnerability is a format string flaw that permits a local attacker on IBM AIX 7.2 or 7.3, and on IBM PowerVM VIOS 4.1, to construct a malicious input that is processed by system components, allowing the attacker to rewrite memory and gain elevated privileges. This outcome compromises confidentiality, integrity, and availability of the affected system as the attacker effectively gains root or administrative control.
Affected Systems
AIX 7.2 and 7.3 in all releases, as well as PowerVM VIOS 4.1. IBM has mitigated the flaw in cumulative Service Packs and Fix Packs: AIX Service Packs SP2 for AIX 7.3 TL04, SP3 for TL03, SP5 for TL02, and SP13 for TL05; AIX 7.2 uses SP13. For VIOS, Fix Packs 4.1.2.20 for VIOS 4.1.2, 4.1.1.30 for VIOS 4.1.1, and 4.1.0.50 for VIOS 4.1.0.
Risk and Exploitability
The CVSS base score of 7.0 indicates a medium‑severity vulnerability and the exploit probability is unknown because EPSS data is not available. The flaw is not listed in CISA’s KEV catalog. Attackers must be local users with authenticated access who can supply crafted input to the vulnerable binary; no remote access is required. Consequently, the risk is significant for systems that run unauthenticated roles or are exposed in shared environments.
OpenCVE Enrichment