CVE-2025-27364

Published Feb 24, 2025

Last updated a month ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-27364 is a critical remote code execution (RCE) vulnerability affecting MITRE Caldera, an open-source adversary emulation platform used by security professionals. This flaw, present in Caldera versions up to 4.2.0 and 5.0.0 (before commit 35bc06e), allows attackers to execute arbitrary code on vulnerable servers without authentication. The vulnerability stems from Caldera's dynamic agent compilation feature, which can be manipulated through crafted web requests to inject malicious code. Exploitation of this vulnerability requires Go, Python, and GCC to be installed on the target system, which are often dependencies for Caldera's full functionality. MITRE has released updated versions of Caldera (5.1.0+ or the master branch) that address this vulnerability and urges users to update immediately.

Description
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands.
Source
cve@mitre.org
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@mitre.org
CWE-78

Social media

Hype score
Not currently trending
  1. 🚨 Critical RCE Vulnerability Discovered in MITRE Caldera (CVE-2025-27364) A critical Remote Code Execution (RCE) vulnerability has been identified in MITRE Caldera, a widely used adversary emulation platform. Read the blog to learn more: https://t.co/E7patWVQSV #GradientCyber

    @GradientCyber

    3 Mar 2025

    23 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Alerta de Seguridad: Ejecución Remota de Código en MITRE Caldera (CVE-2025-27364) https://t.co/8rHjkTgIQD

    @tpx_Security

    3 Mar 2025

    241 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. MITRE Caldera RCE Vulnerability (CVE-2025-27364) Fixed – Patch NOW! A critical flaw allows unauthenticated RCE via HTTPS requests in MITRE Caldera (≤5.0.0). Public PoC & incoming Metasploit module make this a hacker’s dream. ✅ Patch now (v5.1.0) ⚠️ Restrict internet access

    @dCypherIO

    3 Mar 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-CVE-2025-27364: In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability—CVSS 10.0 escalates systems. 25% vulns critical (NVD). 80% systems unpatched (NIST). Enlist with CyberStrike—fast, elite defense: https://t.co/n9BoCWZ9VF

    @taqtics_ai

    3 Mar 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Threat Alert: MITRE Caldera Hit by Critical RCE Flaw (CVE-2025-27364) - Here's What You Need t CVE-2025-27364 CVE-2024-34331 Severity: 🟡 Medium Maturity: 💥 Mainstream Learn more: https://t.co/fZ7x08V3BG #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    1 Mar 2025

    44 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-27364 affects MITRE Caldera #MITRE #Caldera #CVE-2025-27364 https://t.co/1qTZTLZfDm

    @pravin_karthik

    1 Mar 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. ⚠️ Vulnerability Alert: CVE-2025-27364 RCE in MITRE Caldera 📅 Timeline: Disclosure: 2025-02-25, Patch: 2025-02-28 🆔cveId: CVE-2025-27364 📊baseScore: 10.0 📏cvssMetrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H cvssSeverity: Critical 🔴 🛠️exploitMaturity: Proof of… ht

    @syedaquib77

    28 Feb 2025

    28 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨🚨 CVE-2025-27364 (CVSS: 10) – Critical Remote Code Execution Flaw in MITRE Caldera ⚠️ This vulnerability only requires Go, Python, and GCC to be present on the system where the Caldera server is running. 🔥 PoC: https://t.co/N8qmx2qwL2 ZoomEye Dork 👉 app="MITRE Caldera"… ht

    @zoomeye_team

    27 Feb 2025

    76 Impressions

    1 Retweet

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  9. 🚨Alert🚨 CVE-2025-27364 (CVSS 10): Remote Code Execution Flaw Found in MITRE Caldera 🔥PoC:https://t.co/DwtaLFU1kF 📊 500+Services are found on the https://t.co/ysWb28Crld yearly. 🔗Hunter Link:https://t.co/VZbvL5LCYW 👇Query HUNTER : https://t.co/q9rtuGgxk7="MITRE Caldera"… htt

    @HunterMapping

    27 Feb 2025

    1106 Impressions

    2 Retweets

    10 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  10. ⚠️⚠️ CVE-2025-27364 (CVSS 10): Remote Code Execution Flaw Found in MITRE Caldera, PoC Releases 🎯500+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔥PoC: https://t.co/EBm2u1NIlQ 🔗FOFA Link:https://t.co/87iG3jOCpa FOFA Query:app="MITRE-Caldera"… https://t.co/

    @fofabot

    27 Feb 2025

    1623 Impressions

    6 Retweets

    18 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  11. A critical remote code execution (RCE) vulnerability, tracked as CVE-2025-27364, has been discovered in MITRE's Caldera security training platform, affecting all versions since 2017. Users are urged to update to version 5.1.0 or higher to mitigate the risk, as the flaw can be ...

    @CybrPulse

    26 Feb 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. 🧐 VulnWatch Wednesday: CVE-2025-27364 🔓 A critical RCE vulnerability was flagged in @MITREcorp Caldera, a cyber adversary emulation system. 🔧 Fix: The MITRE Caldera team recommends users to immediately pull down the latest version (either Master branch or v5.1.0+) of Caldera

    @kpoireault

    26 Feb 2025

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. CVE-2025-27364 (CVSS 10): Remote Code Execution Flaw Found in MITRE Caldera, PoC Releases https://t.co/P3zXY1pgzY A newly discovered vulnerability in MITRE Caldera, tracked as CVE-2025-27364, has been assigned a critical CVSS score of 10, indicating its severe impact on affected

    @H4ckManac

    26 Feb 2025

    218 Impressions

    3 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  14. 【リンク集:2月25日〜26日のセキュリティ関連ニュース/記事】 <脆弱性> ・CVE-2025-27364(CVSS 10):MITRE Calderaにリモートコード実行の脆弱性が見つかる PoCも公開 https://t.co/xPnnn9PfNC ・マイクロソフト、DNS変更によるEntra ID認証の問題を修正 https://t.co/GBEfhWGPDX… https://t.co/W3LCfkq6Ry

    @MachinaRecord

    26 Feb 2025

    169 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 A critical RCE vulnerability (CVE-2025-27364) affects all versions of MITRE Caldera, allowing unauthenticated attackers to execute arbitrary code on servers. Update to the latest version! 🇺🇸 #MITRECaldera #RCEvulnerability link: https://t.co/sXVIC4soUj https://t.co/axSKUUjG

    @TweetThreatNews

    26 Feb 2025

    59 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🔴 A critical RCE vulnerability (CVE-2025-27364) in MITRE Caldera allows attackers to execute arbitrary code due to authentication flaws. Update to mitigate risks! 🌐 #MITRE #RemoteCodeExecution #USA link: https://t.co/GM4TMqAkb4 https://t.co/uXLDb5KOMy

    @TweetThreatNews

    25 Feb 2025

    45 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  17. ⚠️ Vulnerability Alert: Remote Code Execution Flaw in MITRE Caldera 📅 Timeline: Disclosure: 2025-02-24, Patch: 2025-02-24 📌 Attribution: 🆔cveId: CVE-2025-27364 📊baseScore: 10 📏cvssMetrics: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvssSeverity: Critical 🔴 🛠️exploitMaturity

    @syedaquib77

    25 Feb 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. ⚠️ Vulnerability Alert: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 📅 Timeline: Disclosure: 2025-01-14, Patch: 2025-01-21 📌 Attribution: MITRE 🆔cveId: CVE-2025-27364 📊baseScore: 10 📏cvssMetrics:… https://t.co/lSaNTS1POk

    @syedaquib77

    25 Feb 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. ⚠️ Vulnerability Alert: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 📅 Timeline: Disclosure: 2025-01-14, Patch: 2025-01-21 📌 Attribution: MITRE 🆔cveId: CVE-2025-27364 📊baseScore: 10 📏cvssMetrics:… https://t.co/ct7si2ugBT

    @syedaquib77

    25 Feb 2025

    11 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨CVE Alert: Critical MITRE Caldera Remote Code Execution (RCE) vulnerability🚨 Vulnerability Details: CVE-2025-27364 (CVSS 10/10) MITRE Caldera Remote Code Execution (RCE) vulnerability Impact: A Successful exploit may allows remote attackers to execute arbitrary code on the…

    @CyberxtronTech

    25 Feb 2025

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. CVE-2025-27364 (CVSS 10): Remote Code Execution Flaw Found in MITRE Caldera, PoC Releases https://t.co/4rjwre53lQ

    @Dinosn

    25 Feb 2025

    7053 Impressions

    37 Retweets

    144 Likes

    43 Bookmarks

    2 Replies

    0 Quotes

  22. Critical CVE-2025-27364 MITRE Caldera up to 4.2.0 and 5.0.0 (pre-35bc06e) is vulnerable to RCE via its dynamic agent compilation, allowing attackers to send a crafted API request—using gcc’s -extldflags and sub-commands—to compile and download Sandcat or Manx agents.

    @GrimmAnalyst

    25 Feb 2025

    137 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  23. 🚨CVE-2025-27364: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVSS: 10 https://t.co/WO2yKlZizm

    @DarkWebInformer

    24 Feb 2025

    2280 Impressions

    1 Retweet

    6 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  24. [CVE-2025-27364: CRITICAL] Vulnerability found in MITRE Caldera versions 4.2.0 and 5.0.0 allows remote attackers to execute arbitrary code. Ensure prompt updates to mitigate risks. #CyberSecurity.#cybersecurity,#vulnerability https://t.co/CgG6GZOU5U https://t.co/DA5nSY3G3R

    @CveFindCom

    24 Feb 2025

    67 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes