CVE-2015-0925 is a critical remote code execution vulnerability in iPass Open Mobile for Windows versions up to 2.4.4. The flaw resides in the Software Update Assistant plugin, which exposes a named pipe (\[host]\pipe\IPEFSYSPCPIPE) with overly broad permissions, allowing any authenticated user (including remote Domain Users) to send crafted Unicode strings. By invoking the 'RegisterCOM' command with a DLL pathname (including UNC paths), an attacker can force the service to load and execute arbitrary DLLs via regsrv32.exe as SYSTEM. The vulnerable code path is reached through the named pipe, and the subprocess handling the command fails to properly validate or restrict the DLL path, enabling code injection and execution with elevated privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (ipass_pipe_exec.rb) that exploits a remote code execution vulnerability (CVE-2015-0925) in the IPass Client service on Windows. The exploit abuses a named pipe (\\IPEFSYSPCPIPE) accessible to BUILTIN\Users to instruct the service to load a DLL from an attacker-controlled SMB share. The module sets up an SMB server to host the malicious DLL, then sends a command over the named pipe to trigger the service to load and execute the DLL, resulting in code execution with elevated privileges. The module supports both x86 and x64 Windows targets and leverages Metasploit's payload generation and SMB server capabilities. The exploit is operational and provides remote code execution, but requires SMB access and authentication as a user in the appropriate group. The only fingerprintable endpoint is the named pipe used for exploitation.
This repository contains a single Metasploit module (modules/exploits/windows/local/ipass_launch_app.rb) that exploits a privilege escalation vulnerability (CVE-2015-0925) in the iPass Mobile Client Service (iPlatformService) on Windows. The exploit leverages a named pipe (\\.\pipe\IPEFSYSPCPIPE) that is accessible to normal users and exposes a command (LaunchAppSysMode) allowing arbitrary command execution as SYSTEM. The module checks for the presence and status of the vulnerable service, drops a malicious EXE payload to a writable directory, and uses the named pipe to instruct the service to execute the payload as SYSTEM, resulting in privilege escalation. The exploit is operational and requires a Meterpreter session on a vulnerable Windows system. The only endpoints of note are the named pipe and the service name. The code is well-structured and leverages standard Metasploit mixins for file dropping, privilege escalation, and Windows service interaction.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.