CVE-2025-1095
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 8, 2025
CWE ID 119
Summary
CVE-2025-1095 is a newly identified local privilege escalation (LPE) vulnerability affecting IBM Personal Communications v14 and v15. The issue lies in a Windows service present in the software, which is exploitable by any interactively logged-in users on the target system. Successful exploitation allows elevation of privileges, granting attackers full system access by executing commands in the context of NT AUTHORITY\SYSTEM. Notably, this vulnerability stems from an incomplete remediation of the CVE-2024-25029 issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM Personal Communications
Affected Vendors
- IBM Corporation