Impact
IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.x contain a buffer overflow that can be triggered by a local attacker when certain operations are performed. The flaw allows the attacker to read or write arbitrary memory, which can elevate privileges or cause the system to execute malicious code. This local code execution vulnerability could be used to compromise the host, create persistence, or pivot to other systems on the network. The weakness is identified as CWE‑787, an out‑of‑bounds write.
Affected Systems
The vulnerability affects IBM AIX 7.2 and 7.3 across all service levels prior to the identified service packs, as well as IBM PowerVM VIOS 4.1. The applicable remediation levels are AIX 7.3 TL04 SP2, 7.3 TL03 SP3, 7.3 TL02 SP5, 7.2 TL05 SP13 and VIOS 4.1.2 FP4.1.2.20, 4.1.1 FP4.1.1.30, and 4.1.0 FP4.1.0.50. All earlier levels are indirectly affected because the patches are cumulative.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity with high exploitability. EPSS score is not available, so the public exploit probability cannot be quantified, but it is known to be a local privilege escalation. The vulnerability is not listed in the CISA KEV catalog. Attack likely requires local access, exploitation through a local user with privilege to trigger the vulnerable operation. A successful exploit would allow arbitrary code execution on the host, potentially compromising all dependent workloads.
OpenCVE Enrichment