ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Ivanti EPMM, MDaemon Email Server, Srimax Output Messenger, Zimbra Collaboration, and ZKTeco BioTime flaws to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-38950
Unauthenticated Path Traversal in ZKTeco BioTime iclock API (Arbitrary File Read)

CVE-2023-38950 is a path traversal flaw (CWE-22) in the iclock API of ZKTeco BioTime, confirmed in version 8.5.5, that lets an attacker send a crafted traversal payload to the API endpoint without any authentication. An unauthenticated remote attacker who exploits it gains the ability to read arbitrary files on the BioTime server, with high confidentiality impact but no integrity or availability impact, per the CVSS 7.5 vector. Organizations running affected BioTime deployments, particularly time-and-attendance servers reachable from the internet, are exposed. The flaw has a public proof-of-concept reference, a very high EPSS score of 84.7%, and was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-19, indicating confirmed exploitation in the wild. CISA's required action is to apply vendor mitigations (follow BOD 22-01 guidance for cloud services) or discontinue use of the product if mitigations are unavailable.

Do: Upgrade ZKBioTime to version 9.0.120240617.19506 or later, per the vendor fix. If upgrading is not immediately possible, restrict internet exposure of the iclock API (firewall or reverse proxy) and check logs for unauthenticated requests containing traversal sequences to the endpoint; given CISA's required action for KEV entries, apply mitigations per vendor instructions or discontinue use. Since the flaw allows arbitrary file reads, review whether configuration files or credentials on the BioTime server were reachable and rotate exposed secrets as a precaution.

7.585% KEV PoC
  • zkteco biotime 8.5.5 confirmed affected; fixed in ZKBioTime 9.0.120240617.19506
moderateroughly thousands (1k-10k) of exposed BioTime servers; total install base unknown
CVE-2024-11182
Unauthenticated Cross-Site Scripting (XSS) in MDaemon Email Server Webmail

MDaemon Email Server versions before 24.5.1c contain a cross-site scripting flaw (CWE-79) in its handling of HTML email: JavaScript embedded in an img tag is not properly sanitized. A remote, unauthenticated attacker can trigger it simply by sending a crafted HTML email that a webmail user then opens, requiring no privileges but relying on user interaction. Successful exploitation loads attacker-supplied JavaScript in the context of the webmail user's browser window, which could enable session or credential theft and further intrusions from that user's session. Any organization running an affected MDaemon version with users of its webmail client is affected; MDaemon is a commercial on-premises Windows mail server used mainly by small and mid-sized organizations. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-19, and public reporting ties MDaemon exploitation to Russia-linked APT28 (Fancy Bear) campaigns that targeted the email of high-level Ukrainians and their military suppliers.

Do: Upgrade to MDaemon Email Server 24.5.1c or later, prioritizing installations whose webmail is exposed to the internet, since the flaw is actively exploited and KEV-listed. Review webmail access and message-viewing logs for suspicious activity, especially in organizations that may be targeted by APT28 (Ukrainian government, military, or defense-supply interests). Federal agencies must follow CISA KEV required actions (apply vendor mitigations per instructions and applicable BOD 22-01 guidance, or discontinue use if mitigations are unavailable) by the required due date.

5.318% KEV
  • MDaemon Technologies MDaemon Email Server all versions before 24.5.1c
moderatetens of thousands of on-premises deployments; plausibly on the order of 10,000–100,000 webmail users
CVE-2024-27443
Cross-Site Scripting in Zimbra Collaboration Suite CalendarInvite (Classic Webmail)

CVE-2024-27443 is a cross-site scripting vulnerability (CWE-79) in the CalendarInvite feature of the Zimbra webmail classic user interface in Synacor Zimbra Collaboration Suite (ZCS). It is triggered when a user's browser renders an email containing a crafted calendar header, causing attacker-controlled JavaScript to execute within the webmail session. Successful exploitation allows an attacker to run arbitrary JavaScript in the victim's browser, enabling session/cookie theft and actions performed as the victim inside webmail; no public proof-of-concept is known and CVSS has not yet been scored. Organizations running ZCS where users access mail through the classic webmail UI are affected (deployments restricted to the modern UI are not impacted), though specific affected version ranges have not been published in the available data. The flaw was added to the CISA KEV catalog on 2025-05-19, confirming exploitation in the wild, and EPSS currently estimates a 23.6% probability of exploitation within 30 days (98th percentile).

Do: Update ZCS to the patched release for your branch per Synacor/Zimbra's security advisory (specific fixed version numbers are not included in the available data) and confirm whether the classic webmail UI is enabled for any users. Review webmail access logs for suspicious calendar-invite traffic, and note that federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable.

6.124% KEV
  • Synacor Zimbra Collaboration Suite (ZCS)
mass≈ mass
CVE-2025-27920
Directory Traversal in Srimax Output Messenger Before 2.0.63

Output Messenger versions before 2.0.63 contain a directory traversal flaw (CWE-24) caused by improper handling of file paths in application parameters. An attacker who submits ../ sequences in these parameters can reach files outside the intended directory, potentially retrieving configuration files or other sensitive files from the server. The CVSS vector indicates network access with low privileges is required, so a low-privileged user account is sufficient to trigger the flaw. Any organization running Output Messenger below 2.0.63 is affected, and the flaw has been actively exploited: a Türkiye-aligned APT group reportedly used it as a zero-day against Kurdish military servers in Iraq, deploying Golang backdoors, an activity also observed by Microsoft. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2025-05-19, requiring federal agencies to apply vendor mitigations, follow BOD 22-01 guidance, or discontinue use of the product.

Do: Upgrade Srimax Output Messenger to version 2.0.63 or later per the vendor's instructions, as required by CISA's KEV entry (or follow BOD 22-01 guidance for federal cloud services). Organizations that cannot patch promptly should restrict network access to Output Messenger Server and review affected hosts for signs of compromise, including unexpected Golang backdoor binaries or processes and unauthorized access to or modification of configuration files.

8.82% KEV
  • Srimax Output Messenger all versions before 2.0.63
nicheunknown; likely no more than thousands of on-premises deployments (niche enterprise chat product)
CVE-2025-4428
+1 in the same advisory: …4427
Authenticated Code Injection RCE in Ivanti Endpoint Manager Mobile (EPMM) API

CVE-2025-4428 is a code injection flaw (CWE-94) in the API component of Ivanti Endpoint Manager Mobile (EPMM) that lets an authenticated, low-privileged remote attacker execute arbitrary code by sending crafted API requests. Successful exploitation yields code execution on the MDM server itself (CVSS 8.8, High), which typically holds device inventory and administrative control over an organization's enrolled mobile fleet. Any organization running EPMM 12.5.0.0 or earlier is in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-19, EPSS puts the 30-day exploitation probability at 86% (100th percentile), and public reporting ties limited attacks to the China-linked actor UNC5221, who reportedly began exploiting it alongside the companion API authentication bypass CVE-2025-4427 shortly after disclosure. CISA has also warned that threat actors exploiting these EPMM flaws deploy two malware strains; ransomware involvement has not been confirmed.

Do: Upgrade every EPMM instance running 12.5.0.0 or earlier to the patched release per Ivanti's security advisory, prioritizing internet-facing servers, and note that federal agencies must satisfy the BOD 22-01 required action (patch, apply vendor mitigations, or discontinue use of the product). If patching is delayed, restrict internet exposure of the API and review EPMM logs and the advisory's indicators of compromise, since attackers have chained this flaw with the CVE-2025-4427 authentication bypass and deployed malware. Treat any unpatched, exposed EPMM instance as actively targeted until it is remediated.

8.8
group max
86% KEV
  • Ivanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior (API component; affected platforms unspecified in the source data)
largetens of thousands of enterprise deployments (order of 10k-100k EPMM servers; many are internet-exposed)

Indicators of compromiseAll →

TypeIndicatorContext
ipv411.12.0.5tion. The vulnerabilities have been addressed with versions 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1. The vulnerabilities affec
ipv412.3.0.2ulnerabilities have been addressed with versions 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1. The vulnerabilities affect two unna
ipv412.4.0.2ties have been addressed with versions 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1. The vulnerabilities affect two unnamed open-s
Full article471 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti EPMM, MDaemon Email Server, Srimax Output Messenger, Zimbra Collaboration, and ZKTeco BioTime flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium, DrayTek routers, and SAP NetWeaver flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2025-4427 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
  • CVE-2025-4428 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
  • CVE-2024-11182 (CVSS score: 5.3) MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability. A remote attacker can trigger the flaw by sending an HTML e-mail message with JavaScript in an img tag. This could allow the attacker to load arbitrary JavaScript code in the context of a webmail user’s browser window.
  • CVE-2025-27920 (CVSS score: 7.2) Srimax Output Messenger Directory Traversal Vulnerability that allows attackers to access files outside the intended directory using ../ sequences.
  • CVE-2024-27443 (CVSS score: 6.1) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability. The issue is due to improper input validation. An attacker can use crafted email with a malicious calendar header to trigger JavaScript execution when viewed in the classic webmail interface, risking session hijacking or other attacks.
  • CVE-2023-38950 ZKTeco BioTime Path Traversal Vulnerability. An unauthenticated attacker can exploit the flaw to read arbitrary files via supplying a crafted payload.

In mid-May, Ivanti released security updates to address vulnerabilities CVE-2025-4427 and CVE-2025-4428, in Endpoint Manager Mobile (EPMM) software. The company confirmed that threat actors have chained the flaws in limited attacks to gain remote code execution.

Below is their description:

  • CVE-2025-4427 (CVSS score: 5.3) – An authentication bypass in Endpoint Manager Mobile allowing attackers to access protected resources without proper credentials. 
  • CVE-2025-4428 (CVSS score: 7.2) – A remote code execution vulnerability in Endpoint Manager Mobile allowing attackers to execute arbitrary code on the target system. 

CERT-EU reported both vulnerabilities to the software firm. The company confirmed that threat actors could chain the two vulnerabilities to achieve remote code execution without authentication.

The vulnerabilities have been addressed with versions 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1.  

The vulnerabilities affect two unnamed open-source libraries used in EPMM, the company pointed out that they don’t reside in their code. The company is still investigating the attacks, however, it does not have “reliable atomic indicators” at the time of this writing.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by June 9, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/178140/security/u-s-cisa-adds-ivanti-epmm-mdaemon-email-server-srimax-output-messenger-zimbra-collaboration-and-zkteco-biotime-flaws-to-its-known-exploited-vulnerabilities-catalog.html