Impact
The vulnerability arises from improperly scrubbed environment variables on IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1. A compromised local user can manipulate these variables to inject malicious code that the operating system will execute. This allows the attacker to run arbitrary code with the privileges of the affected process, potentially compromising confidentiality, integrity and availability.
Affected Systems
Affected products are IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1. The specific releases impacted are AIX 7.2 TL05 SP13, AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5. For VIOS the affected levels are 4.1.0 with 4.1.0.50 patch, 4.1.1 with 4.1.1.30, and 4.1.2 with 4.1.2.20. These are cumulative service pack and fix pack releases that contain the fix.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity. EPSS is not available so the exact exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local, inferred from the description that a local attacker must manipulate environment variables. Once the environment variable sanitisation bypass is achieved, arbitrary code runs with the privileges of the local process, potentially enabling privilege escalation. IBM strongly recommends addressing the vulnerability now with the provided patches and reboot or Live Update where necessary.
OpenCVE Enrichment