CVE-2025-65115
8.8Hitachi · JP1/IT Desktop Management
A remote code execution vulnerability exists in multiple Hitachi JP1/IT Desktop Management products due to improper handling of external file paths, allowing attackers with low privileges to execute code.
Executive summary
A remote code execution vulnerability in Hitachi JP1/IT Desktop Management products poses a critical risk to organizational infrastructure by allowing authenticated attackers to execute arbitrary code.
Vulnerability
This vulnerability is categorized as CWE-73, involving the external control of file names or paths. Based on the CVSS vector (PR:L), an authenticated attacker with low privileges can leverage this flaw to achieve remote code execution on the affected Windows systems.
Business impact
The ability to execute arbitrary code on management servers can lead to full system compromise, unauthorized access to sensitive administrative data, and the potential for lateral movement across the network. With a CVSS score of 8.8, this vulnerability represents a high-severity threat that could result in significant operational disruption and total loss of confidentiality, integrity, and availability for the impacted management suites.
Remediation
Immediate Action: Organizations must review the official Hitachi security advisory at https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-118/index.html and apply the specific patches provided for your version of the JP1/IT Desktop Management suite.
Proactive Monitoring: Security teams should monitor system access logs for unusual file path activity or unauthorized execution attempts originating from authenticated service accounts.
Compensating Controls: If patching cannot be performed immediately, restrict network access to the management interfaces to trusted internal segments only and implement endpoint detection and response (EDR) solutions to flag anomalous child processes spawned by the management software.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote code execution, this vulnerability demands immediate attention from IT administrators. Organizations should prioritize the identification of all affected JP1/IT Desktop Management instances and schedule emergency maintenance windows to apply the vendor-supplied patches. Failure to remediate this flaw could leave critical management infrastructure exposed to unauthorized control.
More Hitachi CVEs
Sources
Originally found and disclosed by Ruslan Sayfiev, Denis Faiustov, per the CVE Program record.