Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain a time‑of‑check to time‑of‑use race that allows a local attacker to overwrite critical files and access sensitive data. The vulnerability is a classic TOCTOU flaw (CWE‑367) which can lead to configuration tampering or privilege escalation if an attacker can replace or modify files that the system later uses without re‑validation.
Affected Systems
Affected production environments include IBM AIX versions 7.2.0 through 7.3, with specific Service Packs ranging from 7.3 TL04 SP2 up to 7.3 TL02 SP5 (and 7.2 TL05 SP13). IBM PowerVM Virtual I/O Server versions 4.1.0, 4.1.1, and 4.1.2 are also impacted, requiring Fix Packs 4.1.0.50, 4.1.1.30, or 4.1.2.20 respectively. All affected builds are cumulative and the advisories advise applying the latest cumulative Service Pack or Fix Pack for each tail‑level.
Risk and Exploitability
The vulnerability scores a CVSS of 7, indicating a high severity for local attacks. No EPSS score is available, and it is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet. However, the attack requires local system access and a race condition that is not trivial, so the practical exposure depends on the attacker’s ability to run code on the host. Prompt remediation via the recommended Service Packs or Fix Packs mitigates the risk completely.
OpenCVE Enrichment