CVE-2023-38736: IBM Qradar Wincollect

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM QRadar WinCollect Agent 10.0 through 10.1.6, when installed to run as ADMIN or SYSTEM, is vulnerable to a local escalation of privilege attack that a normal user could utilize to gain SYSTEM permissions. IBM X-Force ID: 262542.

Affected products

  • IBM Qradar Wincollect: from 10.0, before 10.1.7 (fixed in 10.1.7)

Published 2023-09-08. Last modified 2026-06-17.