External risk intelligence

pwn.college DOJO Windows VM Access Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2025-62376

The vulnerability exists in an education platform designed as a web application. Such platforms are typically deployed as internet-facing services to allow remote access for students and users. The affected endpoint, /workspace, is part of the standard web interface of the product, making it commonly accessible via the public internet in its intended deployment pattern.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the pwn.college DOJO cybersecurity education platform could allow unauthorized access to active Windows virtual machines. This issue stems from improper authentication on the `/workspace` endpoint, where user access is not adequately verified.

  • Unauthorized users can access Windows VMs.
  • Critical for educational platforms handling sensitive data.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by accessing the /workspace endpoint without needing any special privileges or authentication. By manipulating URL parameters, an attacker can impersonate any user, bypass password checks, and gain unauthorized access to active Windows virtual machines. This allows them to view and modify data on the Windows machine and access files on the associated Linux home directory.

  • No authentication required for access.
  • Triggered by manipulating URL parameters.
  • Unauthorized access to Windows VMs.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthorized user to access and modify data on any active Windows virtual machine within the pwn.college DOJO platform. The exposure occurs when the `/workspace` endpoint is accessed, as it improperly verifies user credentials, enabling an attacker to impersonate any user and gain full access to their Windows VM and associated Linux home directory.

  • Access to active Windows VMs.
  • Impersonation via the `/workspace` endpoint.
  • Modification of VM and home directory data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The pwn.college DOJO platform's education application owners and infrastructure teams are primarily responsible for addressing this critical authentication bypass vulnerability. The immediate first step is to identify all instances of the DOJO platform, confirm which are internet-facing and actively used for Windows VM access, and then assign ownership for remediation planning.

  • Application owners should manage remediation efforts.
  • Verify all internet-facing Windows VM instances.
  • Plan risk-based remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is pwn.college DOJO?

pwn.college DOJO is an open-source cybersecurity education platform. It provides interactive environments where students learn technical security concepts. These environments often include virtualized operating systems, such as Windows and Linux, to give users hands-on experience in controlled, sandboxed workspaces.

What does CWE-287 mean for CVE-2025-62376?

CWE-287 refers to improper authentication. In this vulnerability, the platform fails to correctly verify the identity of a user before granting access. Instead of checking credentials against a secure database, the system relies on user-supplied information in URL parameters, which an attacker can manipulate to bypass login requirements entirely.

How can an attacker trigger this vulnerability?

An attacker triggers this by interacting with the /workspace endpoint. By crafting specific request parameters, they impersonate another user. This does not require prior administrative rights or valid credentials. If a user does not have an active Windows VM session at the time of the request, there is no active session for the attacker to hijack.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal indicates that pwn.college DOJO is typically deployed as an internet-facing web application. Because the affected /workspace endpoint is part of the standard web interface, any instance reachable over the public internet is considered to have an elevated risk profile compared to those isolated within a private network.

What is the first step to remediate this?

The most important step is to update the platform to the version containing the fix in commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef. Until this is applied, administrative teams should audit their deployments to understand their current exposure level, specifically identifying which instances are publicly accessible and currently support active Windows virtual machine sessions.

References