Ossec · Ossec Hids Agent For Windows · CVE-2024-1244
**Name of the Vulnerable Software and Affected Versions**
OSSEC HIDS agent for Windows versions prior to 3.8.0
**Description**
The issue is related to improper input validation, allowing an attacker with control over the OSSEC server or in possession of the agent's key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.
**Recommendations**
For OSSEC HIDS agent for Windows versions prior to 3.8.0, update to version 3.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the UNC path to minimize the risk of exploitation. Avoid using the OSSEC HIDS agent to connect to untrusted or unknown UNC paths until the issue is resolved.