Impact
A heap buffer overflow in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 allows a remote attacker to execute arbitrary code, potentially compromising confidentiality, integrity and availability of the affected systems. The flaw can be triggered through specially crafted input to a vulnerable component that allocates heap memory without proper bounds checking.
Affected Systems
IBM AIX servers running version 7.2 and 7.3 up through service pack 7.2 TL05 SP13, 7.3 TL04 SP2, 7.3 TL03 SP3, and 7.3 TL02 SP5 are vulnerable. IBM PowerVM VIOS 4.1.0, 4.1.1 and 4.1.2 appliances, including fix pack levels 4.1.0.50, 4.1.1.30 and 4.1.2.20, are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score is currently not available, meaning the exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog. The flaw is inferred to be exploitable remotely via network traffic that can reach the vulnerable process, and a successful exploitation would provide the attacker with full system control. Rebooting the LPAR is required after applying the service pack or fix pack to complete the update.
OpenCVE Enrichment