CVE-2024-25029: IBM Personal Communications code execution
IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to move laterally to affected systems and to escalate their privileges. IBM X-Force ID: 281619.
Other sources
IBM Personal Communications 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to move laterally to affected systems and to escalate their privileges.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25029?
CVE-2024-25029 is rated as critical due to its potential for remote code execution and local privilege escalation.
How do I fix CVE-2024-25029?
To remediate CVE-2024-25029, update IBM Personal Communications to version 15.0.2 or later.
Who is affected by CVE-2024-25029?
CVE-2024-25029 affects users of IBM Personal Communications versions 14.0.6 through 15.0.1.
What type of vulnerability is CVE-2024-25029?
CVE-2024-25029 is a vulnerability that allows for remote code execution and local privilege escalation.
Can unprivileged users exploit CVE-2024-25029?
Yes, unprivileged users with network access can exploit CVE-2024-25029 to run commands with elevated privileges.