CVE-2025-36007
7.8IBM · QRadar SIEM
IBM QRadar SIEM contains a privilege escalation vulnerability due to improper privilege assignment within an update script, potentially allowing local attackers to gain elevated system permissions.
Executive summary
An improper privilege assignment vulnerability in IBM QRadar SIEM 7.5 allows local attackers to elevate their privileges to a higher level.
Vulnerability
The vulnerability involves incorrect privilege assignment (CWE-266) within an update script. An authenticated local attacker with low privileges can exploit this flaw to achieve full system control.
Business impact
This vulnerability carries a CVSS score of 7.8, which indicates a High severity level. Successful exploitation could allow an attacker to compromise the integrity and confidentiality of the SIEM platform, potentially leading to unauthorized data access or the manipulation of security logs, which are critical for enterprise threat detection and incident response.
Remediation
Immediate Action: Update IBM QRadar SIEM to version 7.5.0 UP14 or later as specified in the vendor security advisory.
Proactive Monitoring: Review system logs for unauthorized script executions or unexpected changes to user privileges and system configuration files.
Compensating Controls: Restrict local system access to authorized administrators only and implement strict principle of least privilege policies on the underlying operating system.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given that IBM QRadar serves as a central hub for security monitoring, maintaining the integrity of this platform is paramount. Security teams should prioritize the application of the 7.5.0 UP14 update to eliminate the privilege escalation vector, thereby preventing potential lateral movement or full system takeover by an authenticated local actor.
More IBM CVEs
Sources
Originally found and disclosed by John Zuccato, Rodney Ryan, Chris Shepherd, Vince Dragnea, Ben Goodspeed,Dawid Bak, per the CVE Program record.