CVE-2025-36244: IBM AIX privilege escalation
IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
Other sources
IBM AIX, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36244?
The severity of CVE-2025-36244 is classified as high due to potential unauthorized access to root privileges.
How do I fix CVE-2025-36244?
To fix CVE-2025-36244, upgrade to the latest patched versions of IBM AIX or IBM VIOS as provided by IBM.
Who is affected by CVE-2025-36244?
CVE-2025-36244 affects users of IBM AIX 7.2, 7.3, and IBM VIOS 3.1, 4.1 configured to use Kerberos network authentication.
What causes CVE-2025-36244?
CVE-2025-36244 is caused by improper initialization of critical variables leading to potential unauthorized file write access.
Can CVE-2025-36244 be exploited remotely?
CVE-2025-36244 requires local access to the system, making remote exploitation unlikely.