We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-1095

IBM Personal Communications command execution



Description

IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to escalate their privileges. This vulnerability is due to an incomplete fix for CVE-2024-25029.

Reserved 2025-02-06 | Published 2025-04-08 | Updated 2025-04-09 | Assigner ibm


HIGH: 8.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

Product status

Default status
unaffected

v14, v15
affected

References

www.ibm.com/support/pages/node/7230335 vendor-advisory

cve.org (CVE-2025-1095)

nvd.nist.gov (CVE-2025-1095)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-1095

Support options

Helpdesk Chat, Email, Knowledgebase