CVE-2025-36004: IBM i privilege escalation
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.
Other sources
IBM i could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36004?
CVE-2025-36004 has a critical severity rating due to its potential for allowing elevated privileges.
How do I mitigate CVE-2025-36004?
To mitigate CVE-2025-36004, apply the latest security updates from IBM for affected IBM i versions.
What versions of IBM i are affected by CVE-2025-36004?
CVE-2025-36004 affects IBM i versions 7.2, 7.3, 7.4, and 7.5.
What are the risks associated with CVE-2025-36004?
The risks include unauthorized execution of user-controlled code with administrator privileges which can compromise system security.
Is CVE-2025-36004 commonly exploited in the wild?
As of now, there are no reported cases of CVE-2025-36004 being actively exploited in the wild.