PT-2025-2436 · Wazuh+1 · Wazuh+1

Francescoraimondi

·

Published

2025-02-03

·

Updated

2025-02-11

·

CVE-2024-35177

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Wazuh versions prior to 4.9.0
Description: The issue is related to improper access control in the Wazuh agent for Windows, allowing a local malicious user to potentially exploit this vulnerability by placing a specially crafted DLL file in the installation folder or by replacing the service executable binary itself with a malicious one. This can lead to privilege escalation from a low-privileged user and obtain code execution under the context of NT AUTHORITYSYSTEM. Many DLLs are loaded from the installation folder, and by creating a malicious DLL that exports the functions of a legitimate one, it is possible to escalate privileges.
Recommendations: For versions prior to 4.9.0, upgrade to version 4.9.0 to address the issue. As a temporary workaround, consider restricting access to the installation folder to minimize the risk of exploitation. Avoid using non-default installation paths, and ensure proper ACL is applied to the installation folder.

Exploit

Fix

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-01149
CVE-2024-35177
GHSA-PMR2-2R83-H3CV
GO-2025-3444
OPENSUSE-SU-2025:14732-1
OPENSUSE-SU-2025_0429-1
SUSE-SU-2025:0429-1

Affected Products

Suse
Wazuh