Impact
The flaw is an out‑of‑bounds write that a remote attacker can trigger, enabling arbitrary code execution on affected IBM AIX and IBM PowerVM VIOS systems. This breach is a classic buffer overrun (CWE‑787) that compromises the system’s integrity and could grant an attacker full control of the host.
Affected Systems
IBM AIX 7.2 and 7.3 releases that precede the remediation service packs are vulnerable. For AIX 7.2 this applies to versions before SP13; for AIX 7.3 it covers tiers below SP2 in Tier 4, SP3 in Tier 3, or SP5 in Tier 2. IBM PowerVM VIOS 4.1 releases newer than Fix Packs 4.1.0.50, 4.1.1.30, or 4.1.2.20 are also affected. The advisory identifies these affected versions through the CPE strings for IBM AIX and IBM PowerVM VIOS.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. EPSS data is not available, so the exact probability of exploitation cannot be quantified. Based on the description, the likely attack vector is a remote attacker exploiting the out‑of‑bounds write over the network; the advisory explicitly references a remote attacker. The vulnerability is not catalogued in CISA’s KEV list, yet the vendor strongly urges immediate remediation. The precise privilege or interaction prerequisites are not detailed in the provided description.
OpenCVE Enrichment