Impact
The vulnerability is an out‑of‑bounds write that allows a local attacker to execute arbitrary code on affected IBM systems. An attacker with local access could trigger the flaw to gain code execution privileges, potentially leading to full system compromise.
Affected Systems
IBM AIX 7.2 and AIX 7.3 platforms, as well as IBM PowerVM VIOS 4.1. The issue is present across all sub‑versions of these families that have not been updated to the latest Service Packs or Fix Packs.
Risk and Exploitability
The CVSS score of 6.7 marks the flaw as medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV. Because the flaw requires local access and an out‑of‑bounds write, exploitation would be feasible only for users with sufficient local privileges. Nevertheless, the potential for arbitrary code execution means that unpatched systems remain at risk until the official Service Pack or Fix Pack updates are applied and the system is rebooted or updated via Live Update.
OpenCVE Enrichment