Buffer overflow in Person Communications (PCOMM) - CVE-2024-25029

 

Buffer overflow in Person Communications (PCOMM) - CVE-2024-25029

Published: April 10, 2024


Vulnerability identifier: #VU88407
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25029
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the target system.

The vulnerability exists due to IBM Personal Communications includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). A remote attacker with network access to a target computer to run commands with full privileges in the context of NT AUTHORITYSYSTEM, move laterally to affected systems and escalate privileges.


Affected software

Person Communications (PCOMM)

How to mitigate CVE-2024-25029

Install updates from vendor's website.

Person Communications (PCOMM) - addressed in versions 14.0.7, 15.0.2

External References

Related Security Bulletins