Latest BigAntSoft vulnerabilities #
VulnCheck has reported a vulnerability in BigAntSoft BigAnt Office Messenger. This software is used as an on-premises enterprise chat solution.
This vulnerability, assigned CVE-2025-0364, is rated highly critical, with a CVSS score of 9.8.
Versions of BigAntSoft BigAnt Office Messenger versions up to and including 5.6.06 are vulnerable.
What is the impact? #
Successfully exploiting this vulnerability would allow an attacker to take complete control of the vulnerable system. This vulnerability can be exploited remotely and without authentication.
Are updates or workarounds available? #
There is currently no patch for the vulnerable software. Users are recommended to discontinue use of the software until a patch is available, or limit network access to the service to trusted devices only.
How to find potentially vulnerable BigAnt Office Messenger services with runZero #
From the Services Inventory, use the following query to locate systems running potentially vulnerable software:
_asset.protocol:http AND protocol:http AND _service.last.html.title:="BigAnt Admin"