Impact
IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1 expose a use‑after‑free flaw that allows a remote attacker to run arbitrary code. The vulnerability grants an attacker full control over the affected system, enabling compromise of confidentiality, integrity, and availability. With code execution an attacker could, for example, install persistent malware, exfiltrate data, or disrupt services.
Affected Systems
Affected systems include IBM AIX versions 7.2 and 7.3 at any sublevel, especially the service packs listed for AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13 and earlier releases. IBM PowerVM VIOS 4.1 is affected in all 4.1 releases, including VIOS 4.1.0, 4.1.1, and 4.1.2, and the listed fix‑pack levels (4.1.0.50, 4.1.1.30, 4.1.2.20).
Risk and Exploitability
The CVSS score of 9.8 classifies this as a critical vulnerability, and the lack of an EPSS rating means current exploitation probability data is unavailable. The flaw is not in CISA’s KEV catalog, but its remote nature and high severity indicate significant risk. Attackers would need network access to a vulnerable system and could trigger the flaw via the vulnerable component, resulting in arbitrary code execution.
OpenCVE Enrichment