CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
9.0%
There is a vulnerability in IBM Personal Communications (PCOMM). Personal Communications has addressed the applicable CVE through version update.
CVEID:CVE-2024-25029
**DESCRIPTION:**IBM Personal Communications 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to move laterally to affected systems and to escalate their privileges.
CVSS Base score: 9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/281619 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
PCOMM |
14.0.5 – 14.06_iFix001
PCOMM|
15.0 – 15.01
For Client Fix
Upgrade to fixed updated PCOMM version from the following location:
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | personal_communications | 14.05 | cpe:2.3:a:ibm:personal_communications:14.05:*:*:*:*:*:*:* |
ibm | personal_communications | 14.06 | cpe:2.3:a:ibm:personal_communications:14.06:*:*:*:*:*:*:* |
ibm | personal_communications | 15.0.0 | cpe:2.3:a:ibm:personal_communications:15.0.0:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
9.0%