Impact
IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 are vulnerable to a buffer overflow that allows a remote attacker to execute arbitrary code. Based on the description, it is inferred that the flaw originates from improper handling of user data, identified as CWE‑787, and can be triggered via normal system interfaces.
Affected Systems
IBM AIX 7.2 (Service Pack 13 for TL05) and IBM AIX 7.3 (Service Packs 2 for TL04, 3 for TL03, and 5 for TL02) are affected, as are IBM PowerVM VIOS 4.1. The remediation levels published by IBM include Fix Pack 4.1.0.50 for VIOS 4.1.0, Fix Pack 4.1.1.30 for VIOS 4.1.1, and Fix Pack 4.1.2.20 for VIOS 4.1.2. These pack levels are cumulative and replace earlier patches for all previously disclosed AIX/VIOS security vulnerabilities.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and although the EPSS score is not currently available, the vulnerability is not listed in CISA's KEV catalog, suggesting that publicly available exploits may not yet exist. Nonetheless, its remote execution capability makes it a high‑risk target. Based on the description, it is inferred that an attacker can exploit the buffer overflow through standard AIX or VIOS interfaces without needing local privileges, enabling them to run arbitrary code with the privileges of the affected service.
OpenCVE Enrichment