Impact
The vulnerability is an improper validation of an attacker‑controlled pointer in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1. A local user can trigger the flaw to execute arbitrary code with the privileges of that user. The flaw could compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
AIX 7.2 and 7.3, including Service Pack 2, 3, 5 and Release 7.3 TL04, TL03, TL02, as well as AIX 7.2 TL05, are vulnerable. IBM PowerVM VIOS 4.1, with Fix Packs 4.1.0.50, 4.1.1.30 or 4.1.2.20, is also affected. The patches are cumulative and can be applied via IBM Fix Central; a LPAR reboot is required to complete the SP/FP update, although Live Update on AIX can avoid a reboot.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. EPSS data is not available, so the exact exploitation probability cannot be quantified, but the absence of the vulnerability in CISA's KEV catalog does not reduce its risk. Attackers must possess local access to the system; once the flaw is leveraged, they can run code with the privilege level of the user, potentially affecting any processes running on the system.
OpenCVE Enrichment