Impact
An out‑of‑bounds write in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 allows a local attacker to manipulate memory and gain elevated privileges. The vulnerability can be triggered by an attacker who has local access to the affected system and can exploit the memory corruption to gain elevated privileges; based on the description, it is inferred that the attacker could execute arbitrary code as root, potentially compromising confidentiality, integrity, and availability.
Affected Systems
IBM AIX 7.2 and 7.3, including service packs AIX 7.2 TL05 SP13 and AIX 7.3 TL04 SP2, TL03 SP3, TL02 SP5. IBM PowerVM VIOS 4.1, including Fix Packs VIOS 4.1.0.50, 4.1.1.30, and 4.1.2.20.
Risk and Exploitability
With a CVSS score of 8.4, this vulnerability is considered high severity. EPSS is not available, and the issue is not listed in CISA KEV, indicating no confirmed exploitation in the wild yet. The attack requires local system access and the ability to trigger the out‑of‑bounds write; based on the description, it is inferred that once exploited, the attacker could gain root-level privileges. The required remediation involves patching to the listed cumulative Service Packs or Fix Packs and rebooting the LPAR, or using Live Update on AIX to avoid downtime.
OpenCVE Enrichment