Impact
A local attacker can exploit the improper resolution of symbolic links to gain elevated privileges on IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 systems.
Affected Systems
IBM AIX versions 7.2 and 7.3, including any build below the specified service packs, and IBM PowerVM Virtual I/O Server (VIOS) 4.1, including any build below the listed fix packs. The vulnerability is tied to the operating system's handling of symbolic links when accessed by local users.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, which indicates a high severity for local attacks. The EPSS score is not available. The KEV status shows it is not listed in CISA's Known Exploited Vulnerabilities catalog. IBM strongly recommends addressing the vulnerability immediately. The likely attack vector is a local attacker with sufficient read/write access to symbolic links that are mis‑resolved by the operating system, which may allow escalation of privileges on the affected host. The scope of the impact would cover the system on which the privilege escalation occurs.
OpenCVE Enrichment