QID 379593
QID 379593: IBM Personal Communications (PCOMM) Remote Code Execution (RCE) Vulnerability (7147672)
IBM Personal Communications features virtual terminal (VT) emulation and systems network architecture (SNA) application support and provides a platform to access data and applications on different host systems.
CVE-2024-25029: IBM Personal Communications includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE)
Affected Versions:
IBM Personal Communications 14.0.6
IBM Personal Communications 15.0.1
QID Detection Logic:(Authenticated)
It checks for vulnerable version of IBM Personal Communications by checking product version of "pcomstrt.exe"
Successful exploitation of this allows for a low privileged attacker to move laterally to affected systems and to escalate their privileges.
Solution
The vendor has released a patch which can be found 7147672.
Vendor References
- 7147672 -
www.ibm.com/support/pages/node/7147672
CVEs related to QID 379593
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7147672 |
|