CVE-2025-67223 affects the Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before version 8.3.12. The vulnerability arises because daily activity logs are stored in a publicly accessible directory and use predictable filenames. An unauthenticated remote attacker can retrieve these log files and extract direct virtual paths for uploaded files. Those disclosed paths can then be used to bypass intended access controls and directly download sensitive documents.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python proof-of-concept script and a README describing CVE-2025-67223 in Aranda Service Desk AFS. The exploit is a standalone unauthenticated web/network PoC, not tied to a common exploitation framework. The main script, CVE-2025-67223.py, prompts for a target base URL and a start/end date, generates each date in YYYYMMDD format, requests /AFS/logs/<date>.log for each day, and parses returned log content for lines matching 'FILE UPLOADED : <path>'. It deduplicates extracted paths, normalizes Windows backslashes to URL slashes, prepends /AFS/ServiceDesk/, and outputs the resulting direct-access file URLs. Results are printed and written to a local report file. The exploit does not itself download the exposed files, execute code, or deliver a shell; its capability is enumeration and reconstruction of sensitive file URLs that can then be accessed directly. The README explains the full attack chain: public log exposure, disclosure of relative and absolute file paths, and broken access control on static resources. Overall, the repository’s purpose is to demonstrate and automate exploitation of an information disclosure plus access control weakness in Aranda Service Desk versions prior to 8.3.12, enabling discovery and likely exfiltration of ticket descriptions and attachments.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.