CVE-2025-1095 Details
Description
IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to escalate their privileges. This vulnerability is due to an incomplete fix for CVE-2024-25029.
A local privilege escalation vulnerability has been identified in IBM Personal Communications versions 14 and 15. This issue arises from a Windows service that allows interactively logged-in users to execute commands with full privileges under the NT AUTHORITY\SYSTEM account. As a result, low-privileged attackers can escalate their privileges. The vulnerability is attributed to an incomplete fix for CVE-2024-25029.
Users can upgrade to IBM Personal Communications version 14.0.7 or 15.0.3. Instructions for downloading these versions are available on the IBM Support Fix Central website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7230335 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-420 | Unprotected Alternate Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm personal communications | 14.0.0 15.0.0 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2025 | CVE Modified | [email protected] |
| Aug 13, 2025 | Initial Analysis | [email protected] |
| Apr 8, 2025 | New CVE Received | [email protected] |