PT-2023-9080 · Wazuh · Wazuh Manager

D0Ntrash

·

Published

2023-11-28

·

Updated

2025-01-09

·

CVE-2024-32038

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Wazuh Manager versions 3.8.0 through 4.7.1
Description The issue is related to a buffer overflow hazard in the wazuh-analysisd service when handling Unicode characters from Windows Eventchannel messages. This can be exploited by a remote attacker to execute arbitrary code. The vulnerability is associated with the incorrect handling of XML files containing Unicode characters by the cJSON PrintUnformatted() function.
Recommendations For Wazuh Manager versions 3.8.0 through 4.7.1, update to Wazuh Manager 4.7.2 to resolve the issue. As a temporary workaround, consider restricting the handling of Unicode characters from Windows Eventchannel messages in the wazuh-analysisd service until a patch is applied.

Exploit

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03461
CVE-2024-32038
GHSA-FCPW-V3PG-C327
ZDI-24-397

Affected Products

Wazuh Manager