Impact
A time‑of‑check to time‑of‑use race condition (CWE-367) in IBM AIX 7.2 and 7.3, as well as in PowerVM VIOS 4.1, allows a local attacker to manipulate a file or resource between the check and its use. By exploiting this, the attacker can gain elevated system privileges and execute commands with higher authority, threatening the confidentiality, integrity, and availability of the host.
Affected Systems
The vulnerability affects IBM AIX versions 7.2.0 through 7.3 and all 7.3 Tool Levels, as well as IBM PowerVM VIOS 4.1, including sub‑versions 4.1.0, 4.1.1 and 4.1.2. IBM recommends applying AIX Service Pack levels SP2, SP3, SP5 or SP13, and VIOS Fix Pack releases 4.1.0.50, 4.1.1.30, and 4.1.2.20, which cumulatively contain the fix.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity. The description indicates a local attack vector; no network‑based exploitation path is documented. The EPSS score is not available and the issue is not listed in CISA KEV. Consequently, the privilege‑escalation impact warrants urgent remediation for any affected system.
OpenCVE Enrichment