CVE-2023-26286
published 2023-04-26CVE-2023-26286: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
21.8th percentile
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | vios | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Vulnerabilities in IBM AIX could lead to command injection with elevated privileges
blogs_talos·2023-04-24·CVSS 8.4
CVE-2023-26286 [HIGH] Vulnerability Spotlight: Vulnerabilities in IBM AIX could lead to command injection with elevated privileges
Tim Brown of Cisco Security Advisory EMEA discovered these vulnerabilities and contributed to this blog post.
A Cisco security researcher recently discovered two vulnerabilities in the IBM AIX Unix platforms that could be exploited to inject commands and logs into targeted systems with elevated privileges.
AIX is a more than 20-year-old set of operating systems for Unix that run on various IBM platforms.
TALOS-2023-1690 (CVE-2023-26286) is a vulnerability in AIX’s errlog() syscall functionality that can be triggered if an adversary sends a specially crafted syscall. This could then allow the malicious actor to generate arbitrary logs which can trigger malicious commands to be run with elevated privileges. An adversary could also exploit TALOS-2023-1690 to gain out-of-bounds memory acces
Talos
Vulnerability Spotlight: Vulnerabilities in IBM AIX could lead to command injection with elevated privileges
blogs_talos·2023-04-24·CVSS 8.4
[HIGH] Vulnerability Spotlight: Vulnerabilities in IBM AIX could lead to command injection with elevated privileges
## Vulnerability Spotlight: Vulnerabilities in IBM AIX could lead to command injection with elevated privileges
Tim Brown of Cisco Security Advisory EMEA discovered these vulnerabilities and contributed to this blog post.
A Cisco security researcher recently discovered two vulnerabilities in the IBM AIX Unix platforms that could be exploited to inject commands and logs into targeted systems with elevated privileges.
AIX is a more than 20-year-old set of operating systems for Unix that run on various IBM platforms.
TALOS-2023-1690 (CVE-2023-26286) is a vulnerability in AIX’s errlog() syscall functionality that can be triggered if an adversary sends a specially crafted syscall. This could then allow the malicious actor to generate arbitrary logs which can trigger malicious commands to be
2023-04-26
Published