---
cve: "CVE-2015-0925"
severity: "LOW"
cvss: 3.1
epss: "52.2%"
vendor: "n/a"
kev: false
exploited: false
published: "2015-01-22 14:02:59"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T07:45:40+02:00"
---

# CVE-2015-0925

> 3.1 LOW

## Beschreibung

The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated by a UNC share pathname.

## Exploit-Evidenz

- [EDB-36412 — IPass Control Pipe - Remote Command Execution (Metasploit)](https://www.exploit-db.com/exploits/36412) ✅

## Referenzen

- <http://www.kb.cert.org/vuls/id/110652>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2015-0925) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
