Unauthenticated VM access via unchecked user selection
Published Oct 14, 2025 · Updated Oct 14, 2025
Improper authentication in pwn.college DOJO allows remote attackers to access any active Windows VM through the /workspace endpoint. The view_desktop function accepts a user ID from the URL and generates desktop-windows VNC credentials without requiring the administrator check added for that branch. Exploitation requires a target user with an active Windows VM and grants read and write access to that VM and its associated Linux home directory through the Z: drive.
Summary
What happened
Improper authentication in pwn.college DOJO allows remote attackers to access any active Windows VM through the /workspace endpoint. The view_desktop function accepts a user ID from the URL and generates desktop-windows VNC credentials without requiring the administrator check added for that branch. Exploitation requires a target user with an active Windows VM and grants read and write access to that VM and its associated Linux home directory through the Z: drive.
The record
- CVE
- CVE-2025-62376
- Published
- Oct 14, 2025
- Updated
- Oct 14, 2025
- Vendor
- pwn.college
- Product
- DOJO
- Classifications
- CWE-287, T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Oct 14, 2025CVE publishedPublication date reported by the CVE source.
- Oct 14, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=< 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- GHSA-344w-77p7-gx2c proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo