Executive brief
Srimax Output Messenger, a private instant messaging tool for businesses, contains a security flaw that allows unauthorized access to files on the server. An attacker can exploit this to steal sensitive configuration data or internal documents, potentially compromising the entire communication platform. This vulnerability has been actively exploited in the wild for regional espionage.
Technical details
A directory traversal vulnerability (CWE-24/CWE-22) exists in Srimax Output Messenger versions prior to 2.0.63 due to improper file path handling. By injecting '../' sequences into specific parameters, a network-based attacker can bypass directory restrictions to read or write arbitrary files on the host system. While some assessments suggest low privileges are required, others indicate it may be exploitable without authentication. This flaw has been utilized as a zero-day by threat actors for espionage purposes. Users should update to version 2.0.63 or later to remediate the issue.
Affected products
- Srimax Output Messenger before 2.0.63
Timeline
- 2025-05-05: disclosed: Initial CVE publication
- 2025-05-12: other: Microsoft reports zero-day exploitation by 'Marbled Dust' group
- 2025-05-19: kev added: CISA added to Known Exploited Vulnerabilities catalog
- 2025-05-19: patched: Vendor advisory and fix released in version 2.0.63