Metasploit Wrap-Up 11/07/2025

Nov 7 2025

New module content (3)

Centreon authenticated command injection leading to RCE via broker engine "reload" parameter

Author: h00die-gr3y h00die.gr3y@gmail.com

Type: Exploit

Pull request: #20672 contributed by h00die-gr3y

Path: linux/http/centreon_auth_rce_cve_2025_5946

AttackerKB reference: CVE-2025-5946

Description: Adds an exploit module for Centreon. The vulnerability, an authenticated command injection, will lead to a remote code execution.

Rootkit Privilege Escalation Signal Hunter

Author: bcoles bcoles@gmail.com

Type: Exploit

Pull request: #20643 contributed by bcoles

Path: linux/local/rootkit_privesc_signal_hunter

Description: Expands diamorphine privilege escalation module to other rootkits that use signal handling for privilege escalation.

Windows Persistent Task Scheduler

Author: h00die

Type: Exploit

Pull request: #20660 contributed by h00die

Path: windows/persistence/task_scheduler

Description: This adds a new persistence module for Windows - the task scheduler module. The module will create scheduled tasks depending on the ScheduleType option.

Enhancements and features (2)

  • #20523 from h00die - This updates the upstart persistence to use the new persistence mixin.
  • #20643 from bcoles - Expands diamorphine privilege escalation module to other rootkits, which use signal handling for privilege escalation.

Bugs fixed (1)

  • #20673 from adfoster-r7 - Temporarily pins date dependency to 3.4.1 due to possible issues associated with 3.5.0 to allow for further testing.

Documentation

You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

Read more

Recommended Jobs

Staff Product Designer

19 Chichester St, City Centre, Belfast, United Kingdom, BT1 4JB Product & Engineering
Staff Product Designer – AIWe are leading a major platform transformation in the cybersecurity space—modernizing how security professionals interact with data, systems, and intelligent decision-making tools. We’re building the next generation of A...

Manager, Commercial Sales (Tampa)

Water Street, Tampa, FL, United States, 33602 Sales & BD
 *Actively looking for candidates in the Tampa, FL area* We are looking for an Commercial Sales Manager to lead and grow our South-East Region commercial sales team. In this role, you will be responsible for developing strategic account plans, co...

Sales Development Representative

120 Causeway Street, Boston, MA, United States, 02114 Sales & BD
The Sales Development Representative performs all business development activities within the top of the sales pipeline funnel and is responsible for identifying and qualifying leads, capturing and winning new business pursuits, and engaging in ini...

Field CISO

Remote Location, Germany, 47929 Sales Engineering
We are looking for a Field CISO for Central EMEA with a primary focus on business and market development. This position will play a pivotal role in continuing to scale and grow our Central EMEA region as well as supporting and developing our Enter...

Senior Software Engineer - Python

Remote location, Pune, India, 411001 Product & Engineering
Rapid7 is a publicly traded Cybersecurity company headquartered in Boston, MA with 17 offices around the world. We are excited to be expanding our Global footprint into India and as we build out our Product & Engineering teams, we are looking for ...

Software Engineer II - Python

Remote location, Pune, India, 411001 Product & Engineering
Rapid7 is a publicly traded Cybersecurity company headquartered in Boston, MA with 17 offices around the world. We are excited to be expanding our Global footprint into India and as we build out our Product & Engineering teams, we are looking for ...