OS Command Injection in IBM AIX - CVE-2021-38991
Published: January 10, 2022
Vulnerability identifier: #VU59357
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38991
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation in the lscore command. A local user can pass specially crafted data to the the lscore command and execute arbitrary code with elevated privileges.
Affected software
IBM AIX
IBM VIOS
IBM VIOS
How to mitigate CVE-2021-38991
Install updates from vendor's website.