Skip to main content

Milestone Security Advisory

Milestone Security Advisory

Last Updated: 8 minute read
LanguageEnglish

Milestone’s security advisories transparently list vulnerabilities that have been brought to our attention, as well as vulnerabilities for third-party products or components that Milestone have been inquired about.

If you have identified a vulnerability in our products, you can report it via our Vulnerability form. Before reporting a vulnerability found using a vulnerability scanner tool, we encourage you to consult our Vulnerability scanner guide, to ensure you have followed our recommendations for secure deployments.Vulnerability scanner guide

For more information about how Milestone manages vulnerabilities, and develops secure products and services, see:

Note

On February 6, 2024, Milestone joined the Common Vulnerability and Exposures (CVE®) Program as a CVE Numbering Authority (CNA).

This means that new vulnerabilities discovered hereafter will also be registered in the CVE database.

Date

Headline

CVE Number (if available)

Type

CVSS Score (If available)

Description

May 20, 2026

Windows Defender flags SystemHealth.DataProvider.sys (Husky System Health)

-

Vulnerability

-

Milestone has discovered a security vulnerability in a third-party component used for the Husky System Health. This is due to the usage of the WingRing0 driver in the component.

Husky System Health is a non-vital component and has been discontinued and are no longer distributed. It is recommended that Husky System Health and its related components are uninstalled.

December 16, 2025

CVE-2025-0836 XProtect MIP API broken access control

CVE-2025-0836

Vulnerability

CVSS v3.1 - 6.3

CVSS v4.0 - 5.3

Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix a security vulnerability in MIP Webhooks API. The vulnerability causes users with read-only access to the Management Server to have full access to MIP Webhooks API.

October 28, 2025

CVE-2024-40898: potential risk in SafeKit used by XProtect Management Server Failover (MSF)

CVE-2024-40898

Vulnerability

CVSS v3.1 - 7.5

XProtect 2025 R3 embeds SafeKit version 7.5.2.16, a version upgrade from 7.5.2.7, selected to maintain compatibility and avoid breaking changes introduced in newer SafeKit versions.

Important: The product might be potentially affected by CVE-2024-40898, though there is no known evidence of exploitation in MSF environments.

This is not a vulnerability in Milestone Systems product but a third-party component.

April 15, 2025

CVE-2025-1688 — system configuration password reset

CVE-2025-1688

Vulnerability

CVSS v3.1 - 5.5

CVSS v4.0 - 5.5

Milestone has discovered a security vulnerability in the Milestone XProtect installer that resets system configuration password after the upgrading from older versions using specific installers. The system configuration password is an additional, optional protection that is enabled on the Management Server. Any system upgraded with 2024 R1 or 2024 R2 release installer is vulnerable to this issue. Systems upgraded from 2023 R3 or older with version 2025 R1 and newer are not affected.

April 9, 2025

CVE-2024-12569 — sensitive information in the drivers' log file

CVE-2024-12569

Vulnerability

CVSS v3.1 – 7.8

CVSS v4.0 – 5.2

Milestone has released a new version of the XProtect® Device Pack which fixes a security vulnerability in third-party cameras' drivers. The vulnerability causes logging of used credentials when authentication fails.

March 6, 2025

Milestone Open Network Bridge (ONVIF) security vulnerability

CVE-2021-27392

Vulnerability

CVSS v3.1 – 9.9

Milestone Systems has released a software update for XProtect® VMS which fixes a security vulnerability with unsecured credential storage when using Milestone Open Network Bridge (ONVIF). Milestone Systems recommends applying the available hotfix at the earliest possible opportunity. Versions affected: 2018 R2 - 2020 R3.

November 12, 2024

SQL Client — possible Security Feature Bypass

CVE-2024-0056 

Vulnerability

CVSS v3.1 – 8.7

Milestone has released a software update for Milestone XProtect® VMS which fixes a security vulnerability in a third-party component with a possible Security Feature Bypass where an attacker can perform an adversary-in-the-middle attack between SQL Client and SQL Server.

October 8, 2024

CVE-2024-3506 Camera Driver possible Buffer Overflow

CVE-2024-3506

Vulnerability

CVSS v3.1 – 6.7

CVSS v4.0 – 7.3

Milestone has released a new version of the XProtect® Device Pack which fixes a security vulnerability in selected cameras’ drivers that could cause a buffer overflow under strict conditions. This issue may allow the attacker to execute code with the permissions of the XProtect Recording Server user. No public PoC or exploit is known.

July 12, 2024

RegreSSHion vulnerability — CVE-2024-6387 (FAQ)

-

Information

-

Are Milestone XProtect® VMS products impacted by the regreSSHion vulnerability?

January 17, 2024

Husky IVO — LogoFAIL vulnerability

-

Information

-

This KB article will explain the Milestone Husky IVO series exposure to the LogoFail security vulnerability.

May 9, 2023

Milestone Management Server — possible Remote Code Execution by an authenticated user

-

Vulnerability

CVSS v3.1 – 9.9

Milestone has released a software update for Milestone VMS, which fixes a security vulnerability with a possible Remote Code Execution by an authenticated user on the Management Server service. Versions of XProtect® affected: 2020 R2 - 2023 R1.

May 9, 2023

Milestone Event Server — possible Remote Code Execution by an authenticated user

-

Vulnerability

CVSS v3.1 – 9.9

Milestone has released a software update for Milestone VMS, which fixes a security vulnerability with a possible Remote Code Execution by an authenticated user on the Event Server service. Versions of XProtect® affected: 2020 R2 - 2023 R1.

March 2, 2023

Milestone online services discontinues support for TLS v1.0 and TLS v1.1 protocols

-

Information

-

Due to security concerns, Milestone has decided to deprecate the use of TLS 1.0 and TLS 1.1 for our online services.

November 4, 2022

OpenSSL vulnerabilities (CVE-2022-3602 and CVE-2022-3786) impact on the XProtect VMS

-

Vulnerability

-

In XProtect® VMS 2022 R3 (22.3a and 22.3b), the 3.0.5 version of the OpenSSL library is present in the LPR Server and the Open Network Bridge, and may cause vulnerability. This article explains the details.

November 2, 2022

000001392 Milestone Mobile Server authentication bypass vulnerability

-

Vulnerability

CVSS v3.1 – 9.4

Milestone has released a software update for the Milestone XProtect® VMS which fixes a security vulnerability with a possible authentication process bypass in the Mobile Server. Mobile Server 2022 R2 and 2022 R3 are affected. The vulnerability has been fixed in the latest versions of the XProtect cumulative patches.

June 9, 2022

Missing encryption between Identity Server and SQL Server

-

Vulnerability

CVSS v3.1 – 7.4

Milestone has released a software update for the XProtect® VMS which fixes a security vulnerability that enabled unencrypted communication between the Identity Server and the SQL server. This vulnerability might result in an attacker being able to sniff the traffic between those servers

April 13, 2021

Milestone Open Network Bridge (ONVIF) security vulnerability

-

Vulnerability

CVSS v3.1 – 9.9

Milestone Systems has released a software update for XProtect® VMS which fixes a security vulnerability with unsecured credential storage when using Milestone Open Network Bridge (ONVIF). Milestone Systems recommends to apply the available hotfix at the earliest possible opportunity. Versions affected: 2018 R2 - 2020 R3.

April 4, 2022

000003587 Information about Spring4Shell (CVE-2022-22965)

-

Information

-

Spring4Shell (CVE-2022-22965) is the name of a zero-day vulnerability in the Spring Framework, a popular Java framework involving a critical-severity remote code execution issue.

March 24, 2022

Important update to the XProtect VMS Products Administrator manual — Management Server permissions

-

Information

-

We have made an important update to the XProtect® VMS administrator manual regarding permissions required to access the XProtect Management Server.

February 21, 2022

Log4J vulnerability (FAQ)

-

Information

-

Are Milestone VMS products impacted by the Log4J vulnerability?

November 9, 2021

Arbitrary file access on the DLNA Server

-

Vulnerability

CVSS v3.1 – 8.6

Milestone has released a software update for the XProtect® VMS which fixes a security vulnerability that allowed arbitrary file access on the XProtect DLNA server. This vulnerability might result in an attacker retrieving confidential information from the machine where the DLNA server is installed.

September 17, 2020

CCleaner 5.33 Malware

-

Information

-

On September 12, 2017, a cyber security breach was discovered where some versions of the PC optimization utility CCleaner were found to have their source code illegally modified, with the intention to distribute malware to unsuspecting users. The following versions were compromised: CCleaner v. 5.33.6162 and CCleaner Cloud v. 1.07.3191.

July 22, 2020

Customer Dashboard discontinues support for legacy SSL protocols

-

Information

-

As of November 3, 2020, the Milestone Customer Dashboard will no longer support SSLv3 as it is no longer maintained by OpenSSL. This article will provide details about which versions of XProtect® will be affected, and more.

October 11, 2019

XProtect Smart Client script execution vulnerability

-

Vulnerability

-

A remote code execution vulnerability exists in the Matrix component of the XProtect® Smart Client and the way it handles commands. There are hotfixes available for versions 2016 R3 (10.2b) — 2019 R2 (13.2a) — check KB 19057 for more information.

March 22, 2019

XProtect Configuration API security vulnerability and mitigation

-

Vulnerability

-

When the XProtect® Configuration API is used to modify security settings, it fails to perform the necessary security checks. There are hotfixes available for XProtect VMS versions 2016 R2 (10.1a) - 2019 R1 (13.1a).

June 27, 2018

Meltdown and Spectre attacks

-

Vulnerability

-

It is possible to read system memory without permission on many computers and devices which use Intel, AMD, or ARM processors.

June 1, 2018

Husky M10 privilege escalation issue

-

Vulnerability

-

The issue is that an authorized standard user is able to escalate an account to administrator level by manipulating client-side parameters in the web browser.

April 25, 2018

XProtect®: .NET security vulnerability

-

Vulnerability

-

The Recording Server, Management Server and Management Client in XProtect® (Corporate, Expert, Professional+, Express+, Essential+) use an exploitable .NET Framework Remoting deserialization level.

January 16, 2018

Unsupported MSXML version in XProtect VMS

-

Information

-

XProtect VMS (video management software) products ship with MXSML 4.0 — a version of MSXML which is no longer supported by Microsoft. You can probably safely upgrade to a higher version of MSXML; however you need to be careful and follow the best practices with respect to rollback and post-update testing.

September 13, 2017

ONVIF potential security vulnerability

-

Vulnerability

-

A vulnerability has been discovered in a 3rd-party toolkit which is used to implement ONVIF. Genivia's gSOAP Toolkit versions 2.7 to 2.8.47 are affected.

September 11, 2017

How to identify and remove default XProtect Basic User account

-

Information

-

A default XProtect Basic User account "admin" with a default password may be created during the installation process. To prevent unauthorized access, the XProtect Basic User must be deleted, or the password must be changed.