Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain a heap‑based buffer overflow that permits a remote attacker to execute arbitrary code on the affected system. The vulnerability is listed as CWE-787 and allows full control over the compromised platform by exploiting uncontrolled memory writes. No explicit access requirement is stated in the description, but the overflow occurs in a component exposed to remote input, implying that an attacker must deliver crafted data to trigger the flaw.
Affected Systems
Affected products include IBM AIX 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1, covering all service packs prior to AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13, and VIOS 4.1.0/4.1.1/4.1.2 Fix Packs 4.1.0.50, 4.1.1.30, and 4.1.2.20. Systems running earlier releases of these operating systems without the latest service packs or fix packs are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as a high‑severity vulnerability, and although the EPSS score is not available, the lack of listing in the CISA KEV suggests limited public exploitation data. The flaw is exploitable remotely via network services that provide input to the vulnerable component, requiring an attacker to construct a malicious payload. IBM recommends applying the latest service packs or fix packs immediately, and a logical partition reboot is required after the update (Live Update can avoid a reboot for AIX). Successful exploitation would grant the attacker arbitrary code execution with the privileges of the affected operating system.
OpenCVE Enrichment