PT-2025-25177 · Wazuh · Wazuh Agent For Windows
Rilke Petrosky
·
Published
2024-02-07
·
Updated
2025-06-11
·
CVE-2024-1243
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Wazuh agent for Windows versions prior to 4.8.0
Description
The issue is caused by improper input validation in the Wazuh agent for Windows, allowing an attacker with control over the Wazuh server or agent key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.
Recommendations
For versions prior to 4.8.0, update to version 4.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Wazuh server or agent key to minimize the risk of exploitation. Avoid configuring the agent to connect to untrusted UNC paths until the issue is resolved.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wazuh Agent For Windows