CVE-2016-6079

HIGH

IBM AIX <7.3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-6079. PoCs published by Hector X. Monsegur.

AI-analyzed exploit summary This exploit leverages multiple CVEs (CVE-2009-1786, CVE-2009-2669, CVE-2014-3074) in IBM AIX to escalate privileges via environment variable manipulation and file writes. It targets the SUID binary 'lquerylv' to create a root-owned shell.

Description

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Hector X. Monsegur · bashlocalaix
https://www.exploit-db.com/exploits/40710

This exploit leverages multiple CVEs (CVE-2009-1786, CVE-2009-2669, CVE-2014-3074) in IBM AIX to escalate privileges via environment variable manipulation and file writes. It targets the SUID binary 'lquerylv' to create a root-owned shell.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: IBM AIX 5.3, 6.1, 7.1, 7.2
No auth needed
Prerequisites: Access to a vulnerable AIX system · Presence of the SUID binary '/usr/sbin/lquerylv'
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94090
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037256
Mitigation, Patch, Vendor Advisory x_refsource_confirm
http://aix.software.ibm.com/aix/efixes/security/lquerylv_advisory.asc
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40710/

Scores

CVSS v3 7.8
EPSS 0.0249
EPSS Percentile 82.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (47)
ibm/aix 5.3
ibm/aix 6.1
ibm/aix 7.1
ibm/aix 7.2
ibm/vios 2.2.0.0
ibm/vios 2.2.0.10
ibm/vios 2.2.0.11
ibm/vios 2.2.0.12
ibm/vios 2.2.0.13
ibm/vios 2.2.1.0
... and 37 more
Published Feb 15, 2017
Tracked Since Feb 18, 2026