IBM AIX privilege escalation
CVE-2023-45170
8.4HIGH
Summary
A vulnerability exists in IBM AIX versions 7.2, 7.3, and VIOS version 3.1, allowing a non-privileged local user to exploit the piobe command. This exploitation can lead to unauthorized privilege escalation, enabling attackers to gain elevated access to system functions that are restricted to higher-privileged users. Furthermore, the vulnerability poses a risk of denial of service, potentially disrupting system operations. IBM has acknowledged this issue and provided guidance for mitigation.
Affected Version(s)
AIX 7.2, 7.3, VIOS 3.1
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved