⤷ Title: Mandiant: Triofox Zero-Day Exploited to Gain SYSTEM Access via Antivirus Feature
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 02:59:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_12480 #Gladinet #HTTPHostHeader #Mandiant #RCE #Triofox #UNC6485 #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 02:59:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_12480 #Gladinet #HTTPHostHeader #Mandiant #RCE #Triofox #UNC6485 #zeroday
Penetration Testing Tools
Mandiant: Triofox Zero-Day Exploited to Gain SYSTEM Access via Antivirus Feature
A critical Triofox zero-day (CVE-2025-12480) was exploited by UNC6485. Attackers bypassed auth via Host header, created an admin, and ran code as SYSTEM via the AV check.