PT-2025-25177 · Wazuh · Wazuh Agent For Windows

Rilke Petrosky

·

Published

2024-02-07

·

Updated

2025-06-11

·

CVE-2024-1243

CVSS v4.0

9.5

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Wazuh agent for Windows versions prior to 4.8.0
Description The issue is caused by improper input validation in the Wazuh agent for Windows, allowing an attacker with control over the Wazuh server or agent key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.
Recommendations For versions prior to 4.8.0, update to version 4.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Wazuh server or agent key to minimize the risk of exploitation. Avoid configuring the agent to connect to untrusted UNC paths until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-10438
CVE-2024-1243
GHSA-3CRH-39QV-FXJ7

Affected Products

Wazuh Agent For Windows