Impact
A local attacker can exploit improper privilege management in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1 to gain elevated privileges. The flaw allows escalation to root or administrative level, potentially compromising confidentiality, integrity, and availability of the affected system. The vulnerability is limited to local attack vectors and does not permit remote exploitation according to the available data.
Affected Systems
The vulnerability affects IBM AIX versions 7.2 and 7.3 before the applicable Service Packs and IBM PowerVM VIOS 4.1 before the cited Fix Packs. IBM recommends applying AIX Service Packs such as AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13, as well as PowerVM VIOS Fix Packs 4.1.2 4.1.2.20, 4.1.1 4.1.1.30, and 4.1.0 4.1.0.50. These updates are cumulative and cover prior vulnerabilities.
Risk and Exploitability
The CVSS score of 7.8 denotes a high severity, while the EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog. The risk is confined to local attackers with access to the system, and exploitation requires privilege escalation through the identified mismanagement paths. Patch management or reboot is required to complete the update, and, for VIOS, post‑update migration to Postgres15 is necessary. The absence of a publicly known exploit does not diminish the need for timely remediation.
OpenCVE Enrichment