Local Privilege Escalation in Cisco Unified Communications and Contact Center Solutions
CVE-2025-20112
What is CVE-2025-20112?
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products allows an authenticated, local attacker to escalate privileges to root. This issue arises from excessive permissions granted to system commands, enabling an attacker to execute crafted commands on the underlying operating system. Once exploited, the attacker can escape the restricted shell and gain root access. To carry out this attack successfully, the attacker must have administrative access to the ESXi hypervisor.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Emergency Responder 12.5(1a)
Cisco Emergency Responder 12.5(1)SU1
Cisco Emergency Responder 12.5(1)
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved