Executive brief
IBM AIX and PowerVM VIOS are core operating systems used to run critical enterprise workloads and virtualization infrastructure. An improper privilege management flaw allows a local attacker with user access to execute arbitrary commands with elevated privileges, potentially leading to full system compromise and unauthorized access to sensitive business data and systems.
Technical details
The vulnerability stems from improper privilege management in IBM AIX 7.2/7.3 and PowerVM VIOS 4.1, allowing local attackers to execute arbitrary commands with elevated privileges. The flaw requires local access but no special privileges to trigger, as indicated by the CVSS vector showing PR:L (low privilege required). An authenticated local attacker can exploit this to gain unauthorized command execution, potentially leading to complete system compromise. IBM has released security updates through Service Packs (SPs) and Fix Packs (FPs) to remediate this issue; customers should apply patches immediately to affected systems.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed