Description
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands.
References (6)
Core 6
Core References
Various Sources
https://github.com/mitre/caldera/releases
Various Sources
https://github.com/mitre/caldera/security
Various Sources
https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e
Issue Tracking
https://github.com/mitre/caldera/pull/3129
Scores
CVSS v3
10.0
EPSS
0.2381
EPSS Percentile
97.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (2)
MITRE/Caldera
< 4.2.0
MITRE/Caldera
5.0.0
Published
Feb 24, 2025
Tracked Since
Feb 18, 2026