Directory traversal vulnerability in Srimax Output Messenger allows remote attackers to access sensitive files outside intended directories. This vulnerability is actively exploited by APT group 'Marbled Dust' for regional espionage and is listed in CISA KEV catalog.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-05-05
Added to CISA KEV: 2025-05-19 14 DAYS BETWEEN CVE AND KEV
CVE-2025-27920 is a directory traversal vulnerability affecting the Srimax Output Messenger software [3].
| Feature | Details |
|---|---|
| Vulnerability Type | Directory Traversal (Improper File Path Handling) [4] |
| Affected Versions | All versions prior to 2.0.63?id=CVE-2025-27920?kagi_q=CVE-2025-27920 |
| Exploitation | Active (Zero-day) [2] |
| Impact | Unauthorized access to or execution of arbitrary files [1] |
This vulnerability allows remote attackers to access or execute arbitrary files by manipulating file paths with `../` sequences.
Since April 2024, the threat actor that Microsoft Threat Intelligence tracks as Marbled Dust has been observed exploiting user accounts that have not applied fixes to a zero-day vulnerability (CVE-2025-27920) in the messaging app Output Messenger, a multiplatform chat software. These exploits have rโฆ
CVE-2025-27920 is a recently discovered directory traversal vulnerability affecting Srimax Output Messenger software.
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. ... Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.