CVE-2025-64693: Intercom, Inc Security Point Windows Of Malion

Critical severity, CVSS 9.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Content-Length. Receiving a specially crafted request from a remote unauthenticated attacker could lead to arbitrary code execution with SYSTEM privilege.

Affected products

  • Intercom, Inc Security Point Windows Of Malion: before 7.1.1.9 (fixed in 7.1.1.9)
  • Intercom, Inc Security Point Windows Of Malioncloud: before 7.2.0.1 (fixed in 7.2.0.1)

Published 2025-11-25. Last modified 2026-06-17.