By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
Computing

SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version

News Room
Last updated: 2025/05/07 at 8:10 AM
News Room Published 7 May 2025
Share
SHARE

May 07, 2025Ravie LakshmananVulnerability / IT Service

Cybersecurity researchers have disclosed multiple security flaw in the on-premise version of SysAid IT support software that could be exploited to achieve pre-authenticated remote code execution with elevated privileges.

The vulnerabilities, tracked as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777, have all been described as XML External Entity (XXE) injections, which occur when an attacker is able to successfully interfere with an application’s parsing of XML input.

This, in turn, could permit attackers to inject unsafe XML entities into the web application, allowing them to carry out a Server-Side Request Forgery (SSRF) attack and in worst cases, remote code execution.

Cybersecurity

A description of the three vulnerabilities, according to watchTowr Labs researchers Sina Kheirkhah and Jake Knott, is as follows –

  • CVE-2025-2775 and CVE-2025-2776 – A pre-authenticated XXE within the /mdm/checkin endpoint
  • CVE-2025-2777 – A pre-authenticated XXE within the /lshw endpoint

watchTowr Labs described the vulnerabilities as trivial to exploit by means of a specially crafted HTTP POST request to the endpoints in question.

Successful exploitation of the flaws could enable an attacker to retrieve local files containing sensitive information, including SysAid’s own “InitAccount.cmd” file, which contains information about the administrator account username and plaintext password created during installation.

Armed with this information, the attacker could then gain full administrative access to SysAid as an administrator-privileged user.

To make matters worse, the XXE flaws could be chained with another operating system command injection vulnerability – discovered by a third-party – to achieve remote code execution. The command injection issue has been assigned the CVE identifier CVE-2025-2778.

Cybersecurity

All four vulnerabilities have been rectified by SysAid with the release of on-premise version 24.4.60 b16 in early March 2025. A proof-of-concept (PoC) exploit combining the four vulnerabilities has been made available.

With security flaws in SysAid (CVE-2023-47246) previously exploited by ransomware actors like Cl0p in zero-day attacks, it’s imperative that users update their instances to the latest version.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article New Gemini 2.5 Pro update is so good, Google couldn’t wait until I/O 2025 to release it
Next Article Training Tips from the Force: Applying Police Dog Techniques at Home
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Top 100 Best Budget Buys: Affordable, Tested Tech That’s Actually Worth It
News
Save over $300 on a robot vacuum that’s probably smarter than you
News
Free Script Writing Templates for Professional Screenwriting
Computing
Apple’s latest MacBook Air just fell to $837 for Mother’s Day
News

You Might also Like

Computing

Free Script Writing Templates for Professional Screenwriting

23 Min Read
Computing

Top 10 Clockify Alternatives For Time Tracking & Productivity

26 Min Read
Computing

TikTok faces large-scale content removal after major falling out with Universal Music Group · TechNode

3 Min Read
Computing

Ad Hoc Meeting Essentials: 7 Key Steps for Success |

28 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?