CVE-2025-34324 affects GoSign Desktop 2.4.0 and earlier. The application’s update mechanism distributes an update manifest containing package URLs and SHA-256 hashes, but the manifest itself is not digitally signed. As a result, trust in update metadata depends entirely on the transport layer. In affected versions, TLS certificate validation can be disabled when a proxy is configured. An attacker able to intercept traffic can exploit this condition to replace the legitimate manifest with a malicious one and provide a corresponding update package whose hash matches the attacker-controlled manifest. The client may then download and install the tampered update. This results in arbitrary code execution in the context of the GoSign Desktop user on Windows and macOS, and potentially with elevated privileges on some Linux deployments. The same behavior can also be abused locally by an attacker who can modify proxy settings to force installation of a crafted update.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working proof-of-concept exploit for GoSign Desktop on Debian/Ubuntu amd64, targeting CVE-2025-34324 and CVE-2025-34327. Its purpose is to demonstrate that a local attacker can abuse weak TLS/update validation to man-in-the-middle the application's update mechanism and deliver a malicious Debian package that executes code during installation. Repository structure is small and focused: gosigndesktop_mitm_poc.py is the main exploit, implemented as a mitmproxy addon; deb-src/DEBIAN/control and deb-src/DEBIAN/postinst define the fake Debian update package; the Makefile automates package building, Python virtualenv setup, mitmdump execution on port 8666, and cleanup/unproxy actions; requirements.txt lists mitmproxy and psutil dependencies; README.md documents the vulnerability and usage. The exploit flow is: (1) build a fake package gosigndesktop_6.6.6_amd64.deb, (2) start mitmdump with the addon, (3) modify ~/.gosign/dike.conf to force GoSign Desktop to use 127.0.0.1:8666 as an HTTP proxy, (4) terminate and restart /usr/lib/gosigndesktop/GoSignDesktop so it reloads settings, (5) intercept GET requests to the update manifest endpoint https://rinnovofirma.infocert.it/gosign/download/update and return attacker-crafted JSON advertising version 6.6.6 as a mandatory update, including SHA-256 and size of the local fake package, and (6) intercept GET requests for https://gosignupdates.infocert.it/gosign/standard/gosigndesktop_6.6.6_amd64.deb and serve the local malicious .deb. The payload is intentionally benign for demonstration: the package post-install script writes a timestamped marker and the output of id to /tmp/gosigndesktop_mitm_poc.log. This shows code execution in the package installation context, which the README describes as privilege escalation to root from a local attacker position. The exploit is not merely a detector and is not obviously fake; it contains complete logic for proxy reconfiguration, process restart, manifest forgery, package serving, and payload execution evidence.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.