Impact
An out‑of‑bounds write in the kernel code of IBM AIX and PowerVM VIOS allows an attacker to execute arbitrary code on a target system. Because the flaw can be triggered by untrusted input, a remote user may take control of the operating system, compromising confidentiality, integrity, and availability. The weakness is classified as CWE‑787.
Affected Systems
IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS 4.1 are affected. Patches are available as AIX service packs for 7.3 TL04 SP2, TL03 SP3, TL02 SP5, and 7.2 TL05 SP13, and as VIOS fix packs for 4.1.2.20, 4.1.1.30, and 4.1.0.50. These fix packs are cumulative and can be applied to any earlier impacted level of the top‑level release.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating a critical level of risk. EPSS data is unavailable, so the current exploitation probability is unknown; however, because the flaw permits code execution, it is clearly a high‑impact threat and is not listed in CISA’s KEV catalog. The likely attack vector is remote, over the network, as the flaw can be triggered by a specially crafted input delivered to the vulnerable system. Prompt patching is essential to mitigate the scope of potential compromise.
OpenCVE Enrichment