Local Privilege Escalation Vulnerability in IBM Personal Communications
CVE-2025-1095

8.8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
8 April 2025

Summary

IBM Personal Communications versions 14 and 15 are affected by a local privilege escalation vulnerability caused by an incomplete fix from a prior issue. This flaw allows any user with interactive access to the system to execute commands with elevated privileges, effectively granting them unauthorized access to the NT AUTHORITY\SYSTEM context. Such elevation could lead to significant security risks, including full control over the affected systems.

Affected Version(s)

Personal Communications v14, v15

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.