By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
Computing

SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version

News Room
Last updated: 2025/05/07 at 8:10 AM
News Room Published 7 May 2025
Share
SHARE

May 07, 2025Ravie LakshmananVulnerability / IT Service

Cybersecurity researchers have disclosed multiple security flaw in the on-premise version of SysAid IT support software that could be exploited to achieve pre-authenticated remote code execution with elevated privileges.

The vulnerabilities, tracked as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777, have all been described as XML External Entity (XXE) injections, which occur when an attacker is able to successfully interfere with an application’s parsing of XML input.

This, in turn, could permit attackers to inject unsafe XML entities into the web application, allowing them to carry out a Server-Side Request Forgery (SSRF) attack and in worst cases, remote code execution.

Cybersecurity

A description of the three vulnerabilities, according to watchTowr Labs researchers Sina Kheirkhah and Jake Knott, is as follows –

  • CVE-2025-2775 and CVE-2025-2776 – A pre-authenticated XXE within the /mdm/checkin endpoint
  • CVE-2025-2777 – A pre-authenticated XXE within the /lshw endpoint

watchTowr Labs described the vulnerabilities as trivial to exploit by means of a specially crafted HTTP POST request to the endpoints in question.

Successful exploitation of the flaws could enable an attacker to retrieve local files containing sensitive information, including SysAid’s own “InitAccount.cmd” file, which contains information about the administrator account username and plaintext password created during installation.

Armed with this information, the attacker could then gain full administrative access to SysAid as an administrator-privileged user.

To make matters worse, the XXE flaws could be chained with another operating system command injection vulnerability – discovered by a third-party – to achieve remote code execution. The command injection issue has been assigned the CVE identifier CVE-2025-2778.

Cybersecurity

All four vulnerabilities have been rectified by SysAid with the release of on-premise version 24.4.60 b16 in early March 2025. A proof-of-concept (PoC) exploit combining the four vulnerabilities has been made available.

With security flaws in SysAid (CVE-2023-47246) previously exploited by ransomware actors like Cl0p in zero-day attacks, it’s imperative that users update their instances to the latest version.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article New Gemini 2.5 Pro update is so good, Google couldn’t wait until I/O 2025 to release it
Next Article Training Tips from the Force: Applying Police Dog Techniques at Home
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Female-founded semiconductor AI startup SixSense raises $8.5M | News
News
Dozens of porn sites used by 9m face Ofcom probe after new UK age verifications
News
Apple says Trump’s tariffs are adding another $1 billion to its costs
News
Why PowerBank and Intellistake Are Betting on Bitcoin and Tokenized Energy | HackerNoon
Computing

You Might also Like

Computing

Why PowerBank and Intellistake Are Betting on Bitcoin and Tokenized Energy | HackerNoon

7 Min Read
Computing

COTI Launches Monthly DeCC Space in Collaboration With Secret Network, To Unite Web3 Projects | HackerNoon

5 Min Read
Computing

10 Years Of Ethereum : ETH Meme Coin Pepeto Ends Stage 6 With $5.770.000 Raised In Presale | HackerNoon

3 Min Read
Computing

Pepeto (PEPETO) Might Pump 17,800% And Steal The Show | HackerNoon

6 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?