We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to escalate their privileges. This vulnerability is due to an incomplete fix for CVE-2024-25029.
Reserved 2025-02-06 | Published 2025-04-08 | Updated 2025-04-09 | Assigner ibmCWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
www.ibm.com/support/pages/node/7230335
Support options