Description
This module exploits an unauthenticated remote code execution exploit chain for Commvault, tracked as CVE-2025-57790 and CVE-2025-57791. A command-line injection permits unauthenticated access to the 'localadmin' account, which then facilitates code execution via expression language injection. CVE-2025-57788 is also leveraged to leak the target host name, which is necessary knowledge to exploit the remote code execution chain. This module executes in the context of 'NETWORK SERVICE' on Windows.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/http/commvault/rce_cve_2025_57790_cve_2025_57791msf undefined(rce_cve_2025_57790_cve_2025_57791) > show actions ...actions...msf undefined(rce_cve_2025_57790_cve_2025_57791) > set ACTION < action-name >msf undefined(rce_cve_2025_57790_cve_2025_57791) > show options ...show and set options...msf undefined(rce_cve_2025_57790_cve_2025_57791) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub