IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to escalate their privileges. This vulnerability is due to an incomplete fix for CVE-2024-25029.
History

Tue, 08 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
Description IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to escalate their privileges. This vulnerability is due to an incomplete fix for CVE-2024-25029.
Title IBM Personal Communications command execution
First Time appeared Ibm
Ibm personal Communications
Weaknesses CWE-119
CPEs cpe:2.3:a:ibm:personal_communications:14.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:personal_communications:15.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm personal Communications
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-04-08T15:11:16.272Z

Updated: 2025-04-09T04:00:52.291Z

Reserved: 2025-02-06T21:21:05.157Z

Link: CVE-2025-1095

cve-icon Vulnrichment

Updated: 2025-04-08T15:38:28.013Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T16:15:24.910

Modified: 2025-04-08T18:13:53.347

Link: CVE-2025-1095

cve-icon Redhat

No data.