CVE-2025-9223 is an authenticated command injection vulnerability affecting Zohocorp ManageEngine Applications Manager version 178100 and below. The issue is described as stemming from improper configuration in the Execute Program Action feature, which allows an authenticated user to inject and execute arbitrary operating system commands through that functionality. Based on the available information, the vulnerable component is the Execute Program Action feature within Applications Manager; no more specific function-level details are provided in the source content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for a command execution vulnerability in ManageEngine Applications Manager's 'Execute Program Action' feature. The vulnerability arises from insufficient command validation, allowing attackers to bypass restrictions using absolute paths, environment variables, or script wrappers. The PoC demonstrates how an authenticated attacker can execute arbitrary system commands and exfiltrate data from the target system. The repository contains two files: - README.md: Detailed documentation describing the vulnerability, exploitation methods, example payloads, and usage instructions. - upload_server.py: A standalone Python 3 script that implements a simple HTTP server to receive exfiltrated files. It supports file uploads via POST (to /upload) and PUT (to /upload/[filename]), lists recent uploads, and includes basic security features such as path traversal protection and unique file naming. The main exploit capability is authenticated remote code execution (RCE) on the Applications Manager host, with the ability to exfiltrate files to an attacker-controlled server. The exploit requires network access to the target and valid credentials with permission to use the vulnerable feature. The provided Python server facilitates the exfiltration process by receiving files sent from the compromised host. No detection or scanning functionality is present; this is a pure exploitation PoC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.