Impact
IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 contain a heap‑based buffer overflow that a local attacker can exploit to gain elevated privileges, leading to potential unauthorized system control as described by CWE‑787. The vulnerability allows a user with local access to execute arbitrary code on the affected systems.
Affected Systems
The flaw affects IBM AIX version 7.2.x and 7.3.x, specifically all service packs up to and including AIX 7.3 TL04SP2, AIX 7.3 TL03SP3, AIX 7.3 TL02SP5, AIX 7.2 TL05 SP13, and the corresponding cumulative patch levels described. IBM PowerVM VIOS 4.1.0, 4.1.1, and 4.1.2 are also vulnerable if they are on earlier Fix Pack levels than VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, or VIOS 4.1.0 4.1.0.50.
Risk and Exploitability
The CVSS score of 8.8 classifies this issue as high severity. Although EPSS data is missing, the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. The attack vector requires local access; an attacker would need to execute a crafted payload on the host to trigger the heap overflow and obtain root or higher privileges. Organizations running these products without the latest Service Pack or Fix Pack should consider the risk significant, especially if the systems are not isolated from untrusted users.
OpenCVE Enrichment