Impact
IBM AIX 7.2, AIX 7.3, and PowerVM VIOS 4.1 suffer a stack buffer overflow that can be triggered by a remote attacker to execute arbitrary code with the privileges of the affected process. The flaw is identified as CWE-787 and carries a CVSS score of 9.8, indicating very high severity. An attacker who can reach the vulnerable side of the system could compromise the confidentiality, integrity, or availability of the affected platform.
Affected Systems
The vulnerability affects IBM AIX versions 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1. For AIX, service packs AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, and AIX 7.2 TL05 SP13 contain the fix. For VIOS, the relevant Fix Packs are VIOS 4.1.2 FP 4.1.2.20, VIOS 4.1.1 FP 4.1.1.30, and VIOS 4.1.0 FP 4.1.0.50.
Risk and Exploitability
The CVSS score of 9.8 reflects a high likelihood of a successful exploitation once the conditions are met. No EPSS score is available, but the absence of a KEV listing does not reduce the risk. The overflow can be exploited remotely, typically from over network interfaces or management channels that provide access to the vulnerable process. An attacker does not need local privilege escalation, and the stack corruption allows arbitrary code execution. The required action involves applying the VN service packs and fix packs, rebooting, and performing any necessary post‑update migration steps.
OpenCVE Enrichment