Metasploit Release Notes

Nov 14, 2024
4.22.5-2024111401

Adds additional logging and diagnostic tooling support for Metasploit Pro, as well 10 new modules including SolarWinds Web Help Desk (CVE-2024-28987) and more.

Nov 06, 2024
4.22.5-2024110601

Fixes an issue were users were unable to delete bulk credentials via the select all option when managing credentials for a project.

Oct 28, 2024
4.22.5-2024102801

This release updates the Ruby and nginx components of Metasploit Pro, and includes enhancements for ESC-15 and 4 new modules.

Oct 14, 2024
4.22.4-2024101401

We have updated Metasploit Pro's bruteforce capabilities to now support Kerberos scanning. We have also fixed multiple issues for Windows Server 2022 installations, as well as improved the installation time and bootup stability on all environments. This release also contains 8 new modules.

Sep 16, 2024
4.22.4-2024091601

We have updated Metasploit Pro's bruteforce capabilities to now support LDAP scanning. Metasploit Pro's network scanning capabilities have been improved. This release also includes 7 new modules, such as pgAdmin CVE-2024-3116, Ivanti Virtual Traffic Manager (vTM) CVE-2024-7593, and more. Users that are connecting to a Windows environment to perform their Metasploit Pro updates or installs (either via RDP, SSH, or similar) might have their connections to the server temporarily disconnect during this update - this is required to support the latest network scanning capabilities in Metasploit Pro.

Aug 22, 2024
4.22.3-2024082201

The Jenkins bruteforce capabilities now correctly identify when Jenkins requires authentication. This release also includes 3 new modules, including two SQL injection modules for DIAEnergie and Fortra FileCatalyst, as well as a SPIP Unauthenticated RCE Exploit.

Aug 19, 2024
4.22.3-2024081901

We have improved the stability of Metasploit Pro for Windows environments when starting. The Bruteforce capabilities have performance enhancements to support larger credentials lists. This release includes 8 new modules, such as Apache HugeGraph Server CVE-2024-27348, FortiClient EMS FCTID CVE-2023-48788, and more.

May 03, 2024
4.22.3-2024050201

We have updated the version of Metasploit Framework to include new modules and enhancements.

Apr 17, 2024
4.22.3-2024041701

We have updated the version of Metasploit Framework to include new modules and enhancements.

Apr 03, 2024
4.22.3-2024040301

We have updated the version of Metasploit Framework to 6.4 which enables new PostgreSQL, MSSQL, MySQL and SMB session types as well as providing Kerberos and Meterpreter payload improvements.