# IBM AIX Bellmail Privilege Escalation Vulnerability  \[CVE-2016-8972\]

## Vulnerability Details

CVSS Rating: 7.8 (high)

### CVE-2016-8972

**Disclosing Company:** Rhino Security Labs

**Date:** 02/15/2017

**Status:** Published

**Affected software/version:**

IBM AIX 6.1, 7.1, and 7.2

## Disclosure

### Rhino Security Labs References

[Blog Post: "AIX Bug Hunting Part 2 – Bellmail Privilege Escalation"](/content/research/unix-nostalgia-aix-bug-hunting-part-2-bellmail-privilege-escalation-cve-2016-8972/index.html)

[GitHub: IBM AIX Bellmail Local Root Exploit](https://github.com/RhinoSecurityLabs/Security-Research/blob/master/exploits/IBM/CVE-2016-8972.sh)

[IBM: "Vulnerability in Bellmail Affects AIX"](https://www.ibm.com/blogs/psirt/ibm-security-bulletin-vulnerability-in-bellmail-affects-aix-cve-2016-8972/)

[MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8972)

[NIST](https://nvd.nist.gov/vuln/detail/CVE-2016-8972)

### Disclosure Date

02/15/2017

### Vulnerability Description

Bellmail contained a vulnerability which allowed non-privileged users to escalate privileges through the email archiving functions 's' and 'w'. Due to lax access controls, attackers would be able to overwrite, or create, privileged files on the filesystem.

### Related Disclosures

[IBM AIX lmscode Local Privilege Escalation Vulnerability\[CVE-2016-3053\]](/content/vulnerability-disclosure/ibm-aix-lmscode-vulnerability/index.html)

[IBM AIX lquerylv Local Privilege Escalation Vulnerability\[CVE-2016-6079\]](/content/vulnerability-disclosure/ibm-aix-lquerylv-vulnerability/index.html)

## CVSS Metrics

### CVSS Rating (version 3.0)

**7.8 (High)**

### Impact Score

### Exploitability Score

5.9

1.8

### Attack Vector

Local Privilege Escalation

**Attack Complexity (AC)** Low  
**Privileges Required (PR)** Low  
**User Interaction (UI)** None  
**Scope (S)** Unchanged

**Confidentiality (C)** High  
**Integrity (I)** High  
**Availability (A)** High
