PT-2025-25178 · Ossec · Ossec Hids Agent For Windows

Rilke Petrosky

·

Published

2025-06-11

·

Updated

2025-06-11

·

CVE-2024-1244

CVSS v4.0

9.5

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions OSSEC HIDS agent for Windows versions prior to 3.8.0
Description The issue is related to improper input validation, allowing an attacker with control over the OSSEC server or in possession of the agent's key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.
Recommendations For OSSEC HIDS agent for Windows versions prior to 3.8.0, update to version 3.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the UNC path to minimize the risk of exploitation. Avoid using the OSSEC HIDS agent to connect to untrusted or unknown UNC paths until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-1244

Affected Products

Ossec Hids Agent For Windows