CVE-2025-5030
Ackites KillWxapkg wxapkg File Parser unpack.go processFile os command injection
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 2.3EPSS 2.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
21 mai 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affects the function processFile of the file internal/unpack/unpack.go of the component wxapkg File Parser. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Produtos afetados
Ackites · KillWxapkgQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →