Impact
A flaw in the Management Server API permits a user with edit permissions to run arbitrary code within the context of the Management Server Service. This results in remote code execution, granting full control over the server’s processes and data, compromising confidentiality, integrity, and availability. The weakness is a classic command‑in‑jection issue classified as CWE‑78.
Affected Systems
Milestone Systems XProtect Management Server, as well as the XProtect Recording Server and XProtect Management Client, are vulnerable. The advisory recommends applying the latest cumulative patches that address this issue for all supported releases from 2023 R3 to 2025 R3.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1 % means the likelihood of exploitation is low at present. The vulnerability can be leveraged only by users who already possess edit permissions on the Management Server, so restricting those rights mitigates risk. Because the issue is not listed in KEV, there no known active exploitation in the wild, but the possible remote code execution warrants caution.
OpenCVE Enrichment