PT-2023-9080 · Wazuh · Wazuh Manager
D0Ntrash
·
Published
2023-11-28
·
Updated
2025-01-09
·
CVE-2024-32038
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wazuh Manager versions 3.8.0 through 4.7.1
Description
The issue is related to a buffer overflow hazard in the wazuh-analysisd service when handling Unicode characters from Windows Eventchannel messages. This can be exploited by a remote attacker to execute arbitrary code. The vulnerability is associated with the incorrect handling of XML files containing Unicode characters by the cJSON PrintUnformatted() function.
Recommendations
For Wazuh Manager versions 3.8.0 through 4.7.1, update to Wazuh Manager 4.7.2 to resolve the issue. As a temporary workaround, consider restricting the handling of Unicode characters from Windows Eventchannel messages in the wazuh-analysisd service until a patch is applied.
Exploit
Fix
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wazuh Manager