Vulnerability Description
IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to escalate their privileges. This vulnerability is due to an incomplete fix for CVE-2024-25029.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Personal Communications | 14.0.0 |
| Apple | Macos | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7230335Vendor Advisory
FAQ
What is CVE-2025-1095?
CVE-2025-1095 is a vulnerability with a CVSS score of 8.8 (HIGH). IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target compu...
How severe is CVE-2025-1095?
CVE-2025-1095 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1095?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Personal Communications, Apple Macos, Linux Linux Kernel, Microsoft Windows.