>> IBM AIX "lsmcode" Command Unspecified Local Privilege Escalation Vulnerability
Title : IBM AIX "lsmcode" Command Unspecified Local Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2006-2007 CVE ID : CVE-2006-2647
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-05-28
Technical Description
A vulnerability has been identified in IBM AIX, which could be exploited by local attackers to obtain elevated privileges. This flaw is due to an error in the "lsmcode" command (shipped as part of the "bos.diag.util" fileset), which could be exploited by malicious users to execute arbitrary commands with "root" privileges.