Local Privilege Escalation Vulnerability in IBM Personal Communications
CVE-2025-1095
8.8HIGH
Summary
IBM Personal Communications versions 14 and 15 are affected by a local privilege escalation vulnerability caused by an incomplete fix from a prior issue. This flaw allows any user with interactive access to the system to execute commands with elevated privileges, effectively granting them unauthorized access to the NT AUTHORITY\SYSTEM context. Such elevation could lead to significant security risks, including full control over the affected systems.
Affected Version(s)
Personal Communications v14, v15
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved