Impact
IBM AIX 7.2 and 7.3, together with IBM PowerVM VIOS 4.1, contain a weakness in privilege management that enables a local attacker to run arbitrary commands with elevated rights. The flaw permits the attacker to bypass normal access controls, potentially compromising the confidentiality, integrity, and availability of the affected systems by altering files, installing malware, or disrupting services.
Affected Systems
Affected systems include IBM AIX versions 7.2 and 7.3 across all tickle levels, with cumulative Service Packs such as AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, and AIX 7.2 TL05 SP13. IBM PowerVM VIOS 4.1 is impacted, and the advisory lists Fix Pack levels 4.1 0 .50, 4.1 1 .30, and 4.1 2 .20 as the remediation thresholds.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity and significant potential impact for an exploited local attack. Because the vulnerability requires local access, the attack vector is local privilege escalation. EPSS data is not provided, so the current probability of exploitation remains unknown, but the vulnerability is not listed in the CISA KEV catalog. IBM strongly recommends applying the patches immediately to avoid the risk of privilege abuse. An LPAR reboot is needed after the update, except in AIX where Live Update can mitigate the reboot requirement.
OpenCVE Enrichment