CVE-2025-25364
8.4Speedify · Speedify VPN
A command injection vulnerability in the Speedify VPN XPC service allows local attackers to execute arbitrary commands with root privileges.
Executive summary
A critical command injection vulnerability in the Speedify VPN application for macOS enables local attackers to gain full root-level control over the host system.
Vulnerability
This vulnerability resides in the me.connectify.SMJobBlessHelper XPC service, which fails to properly validate input, allowing an unauthenticated local attacker to execute arbitrary commands.
Business impact
The ability to execute commands with root-level privileges represents a total compromise of the host system. This vulnerability allows an attacker to bypass all security controls, exfiltrate sensitive data, or install persistent backdoors, posing a severe risk to organizational data integrity and system availability. Given the CVSS score of 8.4, this issue is classified as High severity.
Remediation
Immediate Action: Update the Speedify VPN application to the latest version as specified in the vendor security advisory to patch the vulnerable XPC service.
Proactive Monitoring: Monitor system logs for unauthorized execution of processes originating from the Speedify service or unexpected elevation of privileges by local users.
Compensating Controls: Ensure that local access to the workstation is restricted to authorized personnel only, as this vulnerability requires local access to the target system to exploit.
Exploitation status
Public Exploit Available: Exploit_available (unknown).
Analyst recommendation
The risk posed by this vulnerability is significant due to the elevation of privileges to the root level. All administrators should prioritize updating Speedify VPN across all managed macOS endpoints immediately to remove the vulnerable component and prevent potential local exploitation.