Max Severity RCE Vuln in All Versions of MITRE Caldera
ID: 1399e1e7-12d7-591b-81f0-c429babe4843
STIX ID: report--1399e1e7-12d7-591b-81f0-c429babe4843
Feed Name: Dark Reading
Threat Score
A critical unauthenticated remote code execution vulnerability (CVE-2025-27364) affects all versions of MITRE Caldera via its dynamic agent compilation endpoint; an attacker can inject commands when Go, Python, and gcc are present, leading to full system compromise. A PoC has been published (with planned Metasploit module), and MITRE/author recommend immediate upgrade to the master branch or v5.1.0+ and avoiding exposing Caldera servers to the Internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
