CVE-2014-8904

IBM AIX/VIOS <7.1 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-8904. PoCs published by S2 Crew.

AI-analyzed exploit summary This exploit leverages a privilege escalation vulnerability in AIX 7.1 via the lquerylv command. It manipulates the _DBGCMD_LQUERYLV environment variable and symlink to write to /etc/suid_profile, then executes arbitrary commands with elevated privileges.

Description

lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.

Exploits (1)

exploitdb WORKING POC
by S2 Crew · bashlocalaix
https://www.exploit-db.com/exploits/38576

This exploit leverages a privilege escalation vulnerability in AIX 7.1 via the lquerylv command. It manipulates the _DBGCMD_LQUERYLV environment variable and symlink to write to /etc/suid_profile, then executes arbitrary commands with elevated privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: IBM AIX 7.1 (7100-02-03-1334)
No auth needed
Prerequisites: Access to a vulnerable AIX 7.1 system · Ability to execute commands as a non-root user
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62195
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031596
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV67907
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV68070
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99193
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV68082
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV68478
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV67908
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38576/

Scores

EPSS 0.0096
EPSS Percentile 56.9%

Details

CWE
CWE-264
Status published
Products (27)
ibm/aix 5.3
ibm/aix 6.1
ibm/aix 7.1
ibm/vios 2.2.0.10
ibm/vios 2.2.0.11
ibm/vios 2.2.0.12
ibm/vios 2.2.0.13
ibm/vios 2.2.1.0
ibm/vios 2.2.1.1
ibm/vios 2.2.1.3
... and 17 more
Published Jan 15, 2015
Tracked Since Feb 18, 2026