PT-2025-2436 · Wazuh+1 · Wazuh+1

·

CVE-2024-35177

·

Published

2025-02-03

·

Updated

2025-02-11

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Wazuh versions prior to 4.9.0
Description: The issue is related to improper access control in the Wazuh agent for Windows, allowing a local malicious user to potentially exploit this vulnerability by placing a specially crafted DLL file in the installation folder or by replacing the service executable binary itself with a malicious one. This can lead to privilege escalation from a low-privileged user and obtain code execution under the context of NT AUTHORITYSYSTEM. Many DLLs are loaded from the installation folder, and by creating a malicious DLL that exports the functions of a legitimate one, it is possible to escalate privileges.
Recommendations: For versions prior to 4.9.0, upgrade to version 4.9.0 to address the issue. As a temporary workaround, consider restricting access to the installation folder to minimize the risk of exploitation. Avoid using non-default installation paths, and ensure proper ACL is applied to the installation folder.

Exploit

Fix

LPE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01149
CVE-2024-35177
GHSA-PMR2-2R83-H3CV
GO-2025-3444
OPENSUSE-SU-2025:14732-1
OPENSUSE-SU-2025_0429-1
SUSE-SU-2025:0429-1

Affected Products

Suse
Wazuh