CVE-2025-33120
7.8IBM · QRadar SIEM
IBM QRadar SIEM is vulnerable to local privilege escalation due to a misconfigured cronjob that executes with excessive privileges, allowing an authenticated user to gain elevated access.
Executive summary
A critical privilege escalation vulnerability in IBM QRadar SIEM allows authenticated users to compromise system integrity through misconfigured background tasks.
Vulnerability
This vulnerability, categorized as CWE-250 (Execution with Unnecessary Privileges), involves a misconfigured cronjob. An authenticated local user can exploit this flaw to execute commands with elevated privileges, effectively bypassing standard access controls.
Business impact
The ability for an authenticated user to escalate privileges represents a severe security risk, as it permits unauthorized access to sensitive system data and administrative functions. Given the CVSS score of 7.8, this vulnerability could lead to a full system compromise, resulting in data breaches, loss of audit integrity, or total service disruption within the security operations center.
Remediation
Immediate Action: Update IBM QRadar SIEM and QRadar Incident Forensics to version 7.5.0 UP13 IF01 by downloading the relevant patches from the IBM Fix Central portal.
Proactive Monitoring: Review system cron logs and process execution history for suspicious activity or unauthorized task initiation by standard user accounts.
Compensating Controls: Implement strict access control lists on the underlying operating system to limit user interaction with sensitive configuration files and system-level scripts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations must prioritize the application of the provided security patch to mitigate the risk of local privilege escalation. Because this vulnerability affects the core SIEM infrastructure, failure to remediate could allow an attacker to compromise the very tool used to monitor for security threats, rendering the security operations center blind to their actions.
More IBM CVEs
Sources
Originally found and disclosed by John Zuccato, Rodney Ryan, Chris Shepherd, Vince Dragnea, Ben Goodspeed, Dawid Bak, per the CVE Program record.