# CVE-2025-33117

## Summary

- **CVE ID:** CVE-2025-33117
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-73
- **Published:** Jun 19, 2025
- **Last Modified:** Mar 13, 2026

## Description

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12  could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.

## Affected Products

- IBM — QRadar SIEM (7.5)

## References

- [CNA](https://www.ibm.com/support/pages/node/7237317)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.53%
- **EPSS Percentile:** 43.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._