CVE-2025-36244
IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.12%
- CWE
- CWE-454
- Published
- 2025-09-16
- Last modified
- 2026-03-13
Affected products
- IBM AIX
- IBM AIX
- IBM VIOS
- IBM VIOS
Weakness type
Related vulnerabilities
- CVE-2026-54003 — Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
- CVE-2026-48980 — pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic
- CVE-2026-26148 — Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability