Impact
This vulnerability arises from a time‑of‑check to time‑of‑use race condition (CWE‑367) in IBM AIX 7.2, AIX 7.3, and PowerVM VIOS 4.1. A local attacker can exploit the race to execute arbitrary code on the affected systems.
Affected Systems
Affected systems include IBM AIX 7.2 and 7.3 releases and IBM PowerVM VIOS 4.1. The advised remediation levels are IBM AIX Service Packs such as AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13, and IBM PowerVM VIOS Fix Packs 4.1.0.50, 4.1.1.30, and 4.1.2.20, which are cumulative and cover all previously published issues.
Risk and Exploitability
The CVSS score of 7 indicates a medium‑to‑high risk and the vulnerability can be exploited only by a local attacker, as the attack vector is local. The EPSS score is not disclosed, and the vulnerability is not listed in CISA’s KEV catalog, but the presence of a local arbitrary‑code path warrants immediate patching. An LPAR reboot is required to complete the update, though Live Update can avoid rebooting on AIX.
OpenCVE Enrichment