CVE-2007-4004

IBM AIX <5.3 SP6 & 5.2.0 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4004. PoCs published by qaaz.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in IBM AIX's ftp client (CVE-2007-4004) to achieve local privilege escalation. It leverages environment variable manipulation and shellcode execution to spawn a root shell.

Description

Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the overflow in a gets function call. NOTE: the client is setuid root on AIX, so this issue crosses privilege boundaries.

Exploits (1)

exploitdb WORKING POC VERIFIED
by qaaz · clocalaix
https://www.exploit-db.com/exploits/4233

This exploit targets a buffer overflow vulnerability in IBM AIX's ftp client (CVE-2007-4004) to achieve local privilege escalation. It leverages environment variable manipulation and shellcode execution to spawn a root shell.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: IBM AIX ftp client <= 5.3 sp6
No auth needed
Prerequisites: Local access to an IBM AIX system with vulnerable ftp client
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26219
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018465
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=571
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=isg1IZ01812
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35627
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25077
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=isg1IZ01813
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2675
Various Sources x_refsource_confirm
ftp://aix.software.ibm.com/aix/efixes/security/README

Scores

EPSS 0.0085
EPSS Percentile 53.4%

Details

CWE
CWE-119
Status published
Products (2)
ibm/aix 5.2.0
ibm/aix 5.3 sp6
Published Jul 26, 2007
Tracked Since Feb 18, 2026