Impact
IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 contain a heap‑based buffer overflow in undocumented component code that can be triggered by a local authenticated user. Exploitation of this flaw would allow the attacker to gain arbitrary code execution with the privileges of the affected process, potentially compromising system integrity and confidentiality. The weakness is classified as CWE‑787.
Affected Systems
The flaw affects IBM AIX versions 7.2 and 7.3 and IBM PowerVM VIOS 4.1 on all supported hardware. Official IBM service packs and fix packs that provide remediation are SP2 for AIX 7.3 TL04, SP3 for AIX 7.3 TL03, SP5 for AIX 7.3 TL02, SP13 for AIX 7.2 TL05, and fix pack 4.1.2.20 for VIOS 4.1.2, 4.1.1.30 for VIOS 4.1.1, and 4.1.0.50 for VIOS 4.1.0.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium to high severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Because the attack requires local authenticated access, exploitation would typically involve a user with administrative or system privileges on the AIX or VIOS host. Based on the description, the likely attack vector is local interaction with vulnerable processes; no remote code execution is documented.
OpenCVE Enrichment