Cisco Unified Communications Products Privilege Escalation Vulnerability

🚨SEVERITY: MEDIUM — CVSS 5.1Security Advisory

TL;DR 📌

  • A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing crafted commands on the underlying operating…
  • Highest CVSS: 5.1 (Medium).
  • Fix available — see the first fixed release below.
  • CVEs: CVE-2025-20112.

What it is

CVE-2025-20112 is a privilege escalation flaw affecting a range of Cisco Unified Communications and Contact Center Solutions products, including Unified Communications Manager (CM), Unified CM SME, Unified CM IM&Presence, Unity Connection, Emergency Responder, Prime Collaboration Deployment, Customer Collaboration Platform, Finesse, Unified Contact Center Express (CCX), Unified Intelligence Center, and Virtualized Voice Browser.

The root cause is excessive permissions assigned to system commands available within the restricted administrative shell on these platforms. An authenticated local attacker can craft commands that escape the restricted shell and obtain root privileges on the underlying operating system.

Reaching this vulnerability requires administrative access to the ESXi hypervisor hosting the affected virtual appliance. This is not a remote, unauthenticated network attack — it depends on the attacker already having a foothold with hypervisor-level administrative rights, from which they can then escalate to root on the guest OS of the affected Cisco application.

Packaged CCE, Unified CCE, Unified Contact Center Domain Manager, and Unified Contact Center Management Portal are confirmed not affected.

What to do

  • For Unified CM, Unified CM SME, IM&Presence, Unity Connection, Emergency Responder and Prime Collaboration Deployment: releases on 12.5(1) and 14 should migrate to a fixed release; release 15 is fixed in 15SU2.
  • For Customer Collaboration Platform, Finesse, Unified CCX, Unified Intelligence Center and Virtualized Voice Browser: release 12 should migrate to a fixed release; release 15 is not vulnerable.
  • There are no workarounds — the only remediation is upgrading to the fixed release for your product line.
  • Since exploitation depends on ESXi administrative access, tighten and audit who holds hypervisor admin rights on hosts running these appliances; this reduces exposure even before patching is complete.
  • Check the specific bug ID referenced for your product in the advisory for the most current fixed-release detail, as Cisco notes this information may be updated after publication.

Fixed releases

Affected release First fixed release
15 15SU2

For leadership 🧭

Executive summary. This flaw lets someone who already has administrative control of the ESXi hypervisor break out of the restricted admin shell on Unified CM, Unity Connection, Finesse and related appliances to gain full root access. It’s not remotely exploitable on its own, but any organisation with shared or loosely governed hypervisor admin access should schedule the upgrade in a normal maintenance window rather than treat it as urgent.

Why it matters:

  • Root access on the guest OS of Unified CM, Unity Connection, Emergency Responder, Finesse, CCX, Unified Intelligence Center or Virtualized Voice Browser removes the isolation the restricted shell is meant to enforce, giving full control of call-processing or contact-centre infrastructure.
  • Exploitation requires only administrative access to the ESXi hypervisor hosting the appliance, so any environment where hypervisor admin rights are broadly shared or poorly audited effectively extends privileged access into these voice and collaboration platforms.
  • There is no workaround; the excessive command permissions in the restricted shell can only be closed by upgrading to a fixed release, so exposure persists on 12.5(1), 14 and unpatched 12/15 builds until that upgrade happens.
  • Packaged CCE, Unified CCE, CCDM and CCMP are confirmed unaffected, so remediation effort can be focused on the named Unified Communications and other Contact Center products.

Now / Next / Later:

  • Now: Identify which of the affected products (Unified CM, Unified CM SME, IM&Presence, Unity Connection, Emergency Responder, Prime Collaboration Deployment, Customer Collaboration Platform, Finesse, CCX, Unified Intelligence Center, Virtualized Voice Browser) you run and on what release, and review who currently holds administrative access to the ESXi hosts on which they sit.
  • Next: Upgrade 12.5(1) and 14 deployments of Unified CM, Unified CM SME, IM&Presence, Unity Connection, Emergency Responder and Prime Collaboration Deployment, or move to 15SU2 if already on release 15; upgrade release 12 of Customer Collaboration Platform, Finesse, CCX, Unified Intelligence Center and Virtualized Voice Browser to a fixed build (release 15 is not vulnerable for these).
  • Later: Tighten and formally review who is granted ESXi hypervisor administrative rights on hosts running Unified Communications and Contact Center appliances, since that access is the precondition for this class of privilege escalation.

Source