Impact
This vulnerability allows a local attacker to gain elevated privileges on IBM AIX 7.2, AIX 7.3, or the Foundation for PowerVM VIOS 4.1 by exploiting improper handling of symbolic links. The weakness can be exploited by creating or manipulating symbolic links in a context where the system does not correctly validate them, thereby enabling the attacker to execute actions with higher authority than intended. The impact is the potential for full system compromise and abuse of the affected server, affecting confidentiality, integrity, and availability of the host.
Affected Systems
Affected vendors include IBM with its AIX operating system versions 7.2 and 7.3, and PowerVM VIOS version 4.1. Recommended remediation levels are AIX 7.3 TL04SP2, AIX 7.3 TL03SP3, AIX 7.3 TL02SP5, or AIX 7.2 TL05 SP13, as well as PowerVM VIOS Fix Packs VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.0 4.1.0.50. All updates are cumulative and should be applied on top of any earlier affected levels. Post‑update steps include updating Postgres15 for VIOS 4.1.0 and 4.1.1 as needed.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity. EPSS data is not available, but the lack of an EPSS entry does not lower the risk; local privilege escalation remains a significant threat if the system is exposed to physical or remote attackers with local access. The vulnerability is not listed in CISA's KEV catalog, yet the requirement for a local attack and potential for system takeover suggests a high impact if not patched. The attack vector is inferred to be local, requiring the attacker to execute code or commands that enable creation or manipulation of symbolic links on the affected platform.
OpenCVE Enrichment