CVE-2025-12424
Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.32%
- CWE
- CWE-269
- Published
- 2025-10-28
- Last modified
- 2026-03-13
Affected products
- Azure Access Technology BLU-IC2
- Azure Access Technology BLU-IC4
Weakness type
Related vulnerabilities
- CVE-2026-75777 — Multiple vulnerabilities in IBM Aspera Enterprise Webapps
- CVE-2026-87958 — IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions
- CVE-2026-9327 — IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
- CVE-2026-88891 — OpenPanel Read-Only Access Level Enforcement Bypass via Mutations
- CVE-2026-88863 — capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org
- CVE-2026-84042 — Crun: crun: rootful krun with passt executes container payload as host root
- CVE-2026-87998 — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
- CVE-2026-86746 — Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay