← Vulnerability feed

Vulnerability record · CVE-2015-0925 · published 22 January 2015

CVE-2015-0925: iPass Open Mobile Windows client DLL path injection allows code execution

Ipass · Ipass Open Mobile

The iPass Open Mobile client for Windows before 2.4.5 mishandles a DLL pathname supplied in a crafted Unicode string, which is passed to a subprocess reached through a named pipe. A remote authenticated user can therefore cause arbitrary code to load and run on the affected host. The flaw is a code injection issue in a widely deployed enterprise connectivity client, so it matters for managed Windows endpoints.

9.0 CVSS 2.0 High EPSS 52% · top 1.1% CWE-94 · Code injection
9.0CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated by a UNC share pathname.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote authenticated code execution with complete impact and a very high EPSS percentile, though no KEV listing or known exploit reference.

What it is

The iPass Open Mobile client for Windows before 2.4.5 mishandles a DLL pathname supplied in a crafted Unicode string, which is passed to a subprocess reached through a named pipe. A remote authenticated user can therefore cause arbitrary code to load and run on the affected host. The flaw is a code injection issue in a widely deployed enterprise connectivity client, so it matters for managed Windows endpoints.

Impact

An attacker who can authenticate and reach the named pipe gains arbitrary code execution in the context of the affected subprocess, giving full compromise of confidentiality, integrity and availability on the host.

Attack surface

The vector is network-reachable (AV:N) with low complexity and requires authentication (Au:S); no user interaction is indicated. The crafted Unicode string is delivered to a subprocess through a named pipe, as demonstrated with a UNC share pathname.

Exploitation

No CISA KEV listing and no exploit references are present; EPSS is high (0.52195, 98.9th percentile), suggesting elevated likelihood of exploitation activity despite the absence of public exploit tagging.

What to do

  • Upgrade iPass Open Mobile on Windows to version 2.4.5 or later, which is the fixed release named in the advisory.
  • Restrict named pipe access and limit which accounts can reach the client's IPC endpoints.
  • Block or tightly control outbound SMB/UNC access from endpoints so remote DLL paths cannot be resolved.
  • Apply application control or DLL search-order hardening to prevent loading libraries from untrusted paths.
  • Audit and remove unnecessary local accounts that could authenticate to the client service.

Detection

  • Monitor process creation for the iPass client subprocess loading DLLs from UNC or non-standard paths.
  • Alert on named pipe connections to iPass-related pipes from unexpected or remote accounts.
  • Review Windows event logs for suspicious authentication followed by child process execution under the iPass client.
  • Hunt for SMB connections from managed endpoints to untrusted hosts around the time of iPass client activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.kb.cert.org/vuls/id/110652 Third Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/110652 Third Party AdvisoryUS Government Resource

Track CVE-2015-0925 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2015-0925), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.