CVE-2025-1095

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 8, 2025
CWE ID 119

Summary

CVE-2025-1095 is a newly identified local privilege escalation (LPE) vulnerability affecting IBM Personal Communications v14 and v15. The issue lies in a Windows service present in the software, which is exploitable by any interactively logged-in users on the target system. Successful exploitation allows elevation of privileges, granting attackers full system access by executing commands in the context of NT AUTHORITY\SYSTEM. Notably, this vulnerability stems from an incomplete remediation of the CVE-2024-25029 issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM Personal Communications

Affected Vendors

  • IBM Corporation