Impact
The vulnerability is a heap‑based buffer overflow that permits a local attacker to execute arbitrary code within the affected IBM AIX and PowerVM VIOS processes. This flaw aligns with CWE‑787 and can be leveraged to run malicious payloads or elevate privileges if the vulnerable component is running with elevated rights.
Affected Systems
Affected systems include IBM AIX version 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1. The specific service packs and fix packs that address the flaw are AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13, and the corresponding VIOS 4.1.2 FP4.1.2.20, VIOS 4.1.1 FP4.1.1.30, and VIOS 4.1.0 FP4.1.0.50. These updates are cumulative and should be applied to any earlier affected releases.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity assessment. EPSS data is not available, so the likelihood of exploitation cannot be quantified at this time, but the flaw is enabled by local access and is not mitigated by remote isolation alone. The flaw is not yet listed in the CISA KEV catalog, yet the vendor strongly recommends applying the remediation immediately. Attackers who gain local access can exploit this overflow to execute arbitrary code; remediation via the listed APARs and fix packs eliminates the vulnerability.
OpenCVE Enrichment