Impact
IBM AIX 7.2, AIX 7.3, and IBM PowerVM VIOS 4.1 are vulnerable to an out‑of‑bounds write that can allow a remote attacker to achieve arbitrary code execution. This flaw is a classic buffer overrun (CWE‑787) that compromises the integrity of the operating environment and could grant an attacker full control over the affected host.
Affected Systems
Affected are IBM AIX 7.2 and 7.3 releases prior to the service packs listed as remediation levels: AIX 7.2 before SP13, and AIX 7.3 before SP5, SP3, and SP2. The remediation levels are AIX Service Packs SP13 (AIX 7.2 TL05), SP5 (AIX 7.3 TL02), SP3 (AIX 7.3 TL03), and SP2 (AIX 7.3 TL04). For IBM PowerVM VIOS 4.1, all releases before the Fix Packs 4.1.0.50, 4.1.1.30, and 4.1.2.20 are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified from public metrics, but the exploitability is confirmed by the vendor and this vulnerability allows remote code execution. The KEV catalog does not list this bug, but the vendor urges immediate remediation. Attackers would need network access to the affected systems; whether local privilege or user interaction is required is not clearly specified in the publicly available data.
OpenCVE Enrichment