Metasploit Wrap-Up 11/07/2025

Nov 7 2025

New module content (3)

Centreon authenticated command injection leading to RCE via broker engine "reload" parameter

Author: h00die-gr3y h00die.gr3y@gmail.com

Type: Exploit

Pull request: #20672 contributed by h00die-gr3y

Path: linux/http/centreon_auth_rce_cve_2025_5946

AttackerKB reference: CVE-2025-5946

Description: Adds an exploit module for Centreon. The vulnerability, an authenticated command injection, will lead to a remote code execution.

Rootkit Privilege Escalation Signal Hunter

Author: bcoles bcoles@gmail.com

Type: Exploit

Pull request: #20643 contributed by bcoles

Path: linux/local/rootkit_privesc_signal_hunter

Description: Expands diamorphine privilege escalation module to other rootkits that use signal handling for privilege escalation.

Windows Persistent Task Scheduler

Author: h00die

Type: Exploit

Pull request: #20660 contributed by h00die

Path: windows/persistence/task_scheduler

Description: This adds a new persistence module for Windows - the task scheduler module. The module will create scheduled tasks depending on the ScheduleType option.

Enhancements and features (2)

  • #20523 from h00die - This updates the upstart persistence to use the new persistence mixin.
  • #20643 from bcoles - Expands diamorphine privilege escalation module to other rootkits, which use signal handling for privilege escalation.

Bugs fixed (1)

  • #20673 from adfoster-r7 - Temporarily pins date dependency to 3.4.1 due to possible issues associated with 3.5.0 to allow for further testing.

Documentation

You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

Read more

Recommended Jobs

Manager, Enterprise Sales

TX, United States, 73301 Sales & BD
 *Actively looking for candidates in the Dallas TX area* We are looking for an Enterprise Sales Manager to lead and grow our TOLA Region enterprise sales team. In this role, you will be responsible for developing strategic account plans, coaching...

Regional Sales Leader - Germany (North)

Remote Location, Germany, 47929 Sales & BD
Regional Sales Leader - Germany North We are looking for an experienced and people-centric Sales Leader to join our EMEA Sales organisation and be responsible for driving revenue growth across Northern Germany. Located remotely within the region,...

Director, Real Estate and Workplace Experience Operations

120 Causeway Street, Boston, MA, United States, 02114 Business Support
Rapid7 is seeking an experienced Director of Real Estate and Workplace Experience Operations to drive global processes, planning, and execution across our real estate portfolio and workplace operations.This role requires a strategic thinker who al...

Senior Security Engineer

Remote location, Pune, India, 411001 Information Security
Sr. Security Engineer, IT Infrastructure Obsessed with security? Are you looking for a new opportunity to channel your security expertise into building, integrating, and automating security controls across cloud and on-premise environments? Do yo...

Enterprise Account Executive

1st Floor, Reading, United Kingdom, RG7 4SA Sales & BD
Enterprise Account Executive Rapid7 is seeking a curious, customer-centric, and target-driven Enterprise Account Executive to join our UKI sales team. In this role, you will be responsible for growing your territory by acquiring new enterprise cu...

Lead Product Manager

19 Chichester St, City Centre, Belfast, United Kingdom, BT1 4JB Product & Engineering
Are you a Product Professional who is passionate about making a measurable impact through delivering innovative solutions?  Are you motivated to improve customer experiences to help them better manage their security posture?  Do you want to join a...