Impact
IBM AIX 7.2, AIX 7.3 and PowerVM VIOS 4.1 contain an improper privilege management flaw that allows a local attacker to gain elevated privileges. The weakness is classified as CWE-269 and permits the attacker to execute actions with higher authorization than intended, potentially leading to system compromise or unauthorized data modification.
Affected Systems
Affected products include IBM AIX versions 7.2.0, 7.2, 7.3.0, and 7.3, as well as IBM PowerVM VIOS versions 4.1.0, 4.1, and 4.1.2. IBM recommends applying AIX Service Packs such as AIX 7.3 TL04SP2, AIX 7.3 TL03SP3, AIX 7.3 TL02SP5, or AIX 7.2 TL05 SP13, and PowerVM VIOS Fix Packs 4.1.2.20, 4.1.1.30, and 4.1.0.50. These packages are cumulative and include all previous security fixes for the affected lines.
Risk and Exploitability
The CVSS score of 7 indicates medium‑to‑high severity, and the EPSS score is not reported which suggests limited public exploitation data. The vulnerability is exploitable only by users with local access, but once escalated, the attacker can attain root or administrative privileges and perform destructive or damaging actions on the system.
OpenCVE Enrichment