Impact
IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 are vulnerable to a remote stack buffer overflow that can be exploited by an attacker to execute arbitrary code without authentication. The flaw allows untrusted network input to overwrite control data on the stack, leading to remote code execution. The CVSS score of 8.8 indicates a high severity impact, and the vulnerability can compromise system integrity and confidentiality if exploited.
Affected Systems
The affected products are IBM AIX version 7.2 and 7.3 (all baseline builds prior to the service packs listed) and IBM PowerVM VIOS 4.1 (including the base 4.1.0, 4.1.1, and 4.1.2 releases). IBM recommends applying the following remediation levels: for AIX, Service Pack 2, 3, 5, or 13 depending on the build; for VIOS, Fix Pack 4.1.2.20, 4.1.1.30, or 4.1.0.50, respectively. These patches are cumulative and replace all previous fixes for these platforms.
Risk and Exploitability
The risk is high due to the CVSS score of 8.8, and the lack of an available EPSS score indicates that specific exploitation probability is unknown but potentially significant. The vulnerability is not currently listed in the CISA KEV catalog, but IBM stresses immediate remediation. Exploitation appears to be achievable remotely over network interfaces, requiring no special privileges beyond reach to vulnerable services. The stack overflow suggests that an attacker can hijack execution flow to run arbitrary code on the affected host, which can be leveraged for privilege escalation, data exfiltration, or further network compromise.
OpenCVE Enrichment