CVE-2025-33112: IBM AIX command execution
IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.
Other sources
IBM AIX's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33112?
CVE-2025-33112 has a high severity due to its potential for local user exploitation leading to arbitrary code execution.
How do I fix CVE-2025-33112?
To fix CVE-2025-33112, update your IBM AIX to version 7.3 TL4 or later and IBM VIOS to version 4.1.2 or later.
Who is affected by CVE-2025-33112?
CVE-2025-33112 affects non-privileged local users of IBM AIX 7.3 TL3 and IBM VIOS 4.1.1.
What type of vulnerability is CVE-2025-33112?
CVE-2025-33112 is a local code execution vulnerability caused by improper neutralization of pathname input.
Can CVE-2025-33112 be exploited remotely?
CVE-2025-33112 cannot be exploited remotely as it requires local access to the affected systems.