Palo Alto Networks Unit 42 reported CVE-2025-0921, a medium-severity (CVSS 6.5) vulnerability in Mitsubishi Electric Iconics Digital Solutions GENESIS64 (Iconics Suite) affecting Windows deployments 10.97.2 and earlier. The issue involves unnecessary privileges across multiple services, enabling misuse of privileged file system operations that could corrupt critical binaries and lead to integrity/availability impact, including a potential denial-of-service (DoS) condition; Unit 42 coordinated disclosure with Iconics, and the vendor published mitigations/workarounds intended to address the reported issues.
Separately, reporting highlighted a CISA warning on CVE-2025-26385, a critical (CVSS 10.0) vulnerability in Johnson Controls Metasys building automation components (including ADS/ADX, SCT, CCT, and certain NAE/LCS engines across specified version ranges). The flaw is described as a remote SQL injection / remote SQL execution condition that could allow unauthorized SQL command execution, potentially enabling alteration or loss of data used to manage building environments; Johnson Controls and CISA recommended applying the vendor patch (e.g., GIV-165989 via the License Portal) and following compensating controls where patching is not immediately possible.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The vendor security team coordinated disclosure with the researchers and released an advisory and workaround that reportedly mitigates all vulnerabilities reported during the assessment. This marked the official vendor response to the ICONICS Suite issues.
Researchers showed that CVE-2025-0921 can be chained with CVE-2024-7587 by modifying a writable configuration file and using a crafted symbolic link to redirect logging output into sensitive files such as the Windows cng.sys driver. Triggering a test SMS or alert can overwrite the target binary and leave Windows unable to boot after restart.
Unit 42 disclosed CVE-2025-0921, a medium-severity vulnerability in Mitsubishi Electric Iconics Digital Solutions GENESIS64/Iconics Suite that allows privileged file system operations in the Pager Agent component. A local low-privileged attacker could abuse it to overwrite critical system binaries, causing denial of service and loss of integrity or availability.
Johnson Controls made the Metasys patch for GIV-165989 available through its License Portal and, along with CISA, urged immediate patching. For systems that cannot be patched right away, the advisory recommended closing inbound TCP port 1433, segmenting networks, and avoiding exposure to untrusted networks.
CISA issued a warning for CVE-2025-26385, a CVSS 10.0 SQL injection vulnerability affecting Johnson Controls Metasys Application and Data Server and related configuration tools. The flaw could allow remote SQL execution to alter or destroy data used to control physical building environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.