Impact
A heap buffer overflow in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 permits a local attacker to obtain elevated privileges on the affected systems. The vulnerability can lead to unauthorized system control and may compromise the integrity and confidentiality of the operating environment. The weakness is categorized as a buffer over-read or buffer overflow (CWE‑787).
Affected Systems
Vulnerable versions include IBM AIX 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1. The advisory lists Service Pack levels for AIX (e.g., SP2 for AIX 7.3 TL04, SP3 for AIX 7.3 TL03, SP5 for AIX 7.3 TL02, SP13 for AIX 7.2 TL05) and Fix Pack levels for VIOS (e.g., 4.1.2.20 for VIOS 4.1.2, 4.1.1.30 for VIOS 4.1.1, 4.1.0.50 for VIOS 4.1.0).
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of the privilege escalation. The EPSS score is not available, so the current estimated likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog, but the advisory recommends addressing it immediately. Because the attack vector is local, an attacker must have physical or local network access to the target. The advisory notes that a reboot or Live Update is required for the Service Pack / Fix Pack application, and additional steps are needed for VIOS to migrate to Postgres15 after patching.
OpenCVE Enrichment