PT-2025-15442 · Ibm · Ibm Personal Communications
Published
2025-04-08
·
Updated
2025-09-29
·
CVE-2025-1095
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
IBM Personal Communications versions 14 through 15
Description:
The issue allows any interactively logged-in users on the target computer to run commands with full privileges in the context of NT AUTHORITYSYSTEM. This enables a low-privileged attacker to escalate their privileges. The problem is due to an incomplete fix for a previous issue.
Recommendations:
For versions 14 and 15, consider restricting access to the Windows service until a complete fix is available.
As a temporary workaround, limit interactive logins to minimize the risk of exploitation.
Fix
LPE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Personal Communications