AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-1095

HIGH · CVSS 8.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-04-08 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects Windows.

CVE
CVE-2025-1095
Severity
HIGH
CVSS
8.8
EPSS
0.14%
Windows

Original NVD Description

IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to escalate their privileges. This vulnerability is due to an incomplete fix for CVE-2024-25029.

Related CVEs

Other vulnerabilities affecting the same vendor(s)