A critical zero-day vulnerability in BigAnt Server (CVE-2025-0364) allows unauthenticated attackers to execute arbitrary code on affected systems via a chain of SaaS registration abuses and PHP file uploads.
See also: Zero-Day Windows driver vulnerability allows remote access

The flaw, discovered by VulnCheck researchers during an analysis of a poor CVSS score for CVE-2024-54761 , affects all versions ≤5.6.06 of the Windows-based enterprise chat platform.
The exploit chain starts with a default SaaS registration portal at /index.php/Home/Saas/reg_email.html, which allows for the creation of a corporate account after solving a basic CAPTCHA challenge. The attackers use this to create administrative accounts associated with SaaS organizations controlled by the attackers.
The registration process exposes critical session variables through debug endpoints such as /index.php/Addin/login/index.html, allowing UUID extraction for SaaS activation.
After registration, attackers manipulate session cookies to compromise the SaaS environment. This forces the server to bind the session to the malicious SaaS organization, allowing access to the Cloud Drive add-on .
See also: XE Hacker Group exploits VeraCore Zero-Day
The system incorrectly validates file uploads to the plugin module, accepting PHP files without authentication checks.

The vulnerability arises from multiple architectural flaws:
Insecure Defaults: The SaaS enrollment portal remains active without installation hardening, using predictable credentials (admin/enrollment password) to access Cloud Drive.
Session Management Failures: The sp_saas_id() function in site.php exposes UUIDs via unauthenticated API demo pages, allowing SaaS environment compromise
Unlimited File Uploads: The Cloud Drive module (Application/Addin/Controller/CloudController.class.php) lacks file type validation, allowing PHP to be executed directly in C:\Program Files (x86)\BigAntSoft\IM Console\im_webcserversdatadot.
See also: 7-Zip MotW bypass used in zero-day attacks against Ukraine
A zero-day vulnerability refers to a security vulnerability in software or a system that is unknown to its manufacturers or users. The term “zero-day” refers to the fact that the vulnerability is unknown or unexploited before the manufacturer is aware of it and patches it. These vulnerabilities are particularly dangerous because there is no fix or protection for the attacks that could exploit them. Attackers can exploit the vulnerability to gain unauthorized access, execute malicious software, steal data, or cause other damage.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
