CVE-2016-8972

HIGH

IBM AIX <7.3 - Privilege Escalation

Title source: llm

Description

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.

Exploits (1)

exploitdb WORKING POC
by Hector X. Monsegur · bashlocalaix
https://www.exploit-db.com/exploits/40950

Scores

CVSS v3 7.8
EPSS 0.0063
EPSS Percentile 70.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (45)
ibm/aix 6.1
ibm/aix 7.1
ibm/aix 7.2
ibm/vios 2.2.0.0
ibm/vios 2.2.0.10
ibm/vios 2.2.0.11
ibm/vios 2.2.0.12
ibm/vios 2.2.0.13
ibm/vios 2.2.1.0
ibm/vios 2.2.1.1
... and 35 more
Published Feb 15, 2017
Tracked Since Feb 18, 2026