PT-2025-25178 · Ossec · Ossec Hids Agent For Windows
Rilke Petrosky
·
Published
2025-06-11
·
Updated
2025-06-11
·
CVE-2024-1244
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
OSSEC HIDS agent for Windows versions prior to 3.8.0
Description
The issue is related to improper input validation, allowing an attacker with control over the OSSEC server or in possession of the agent's key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.
Recommendations
For OSSEC HIDS agent for Windows versions prior to 3.8.0, update to version 3.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the UNC path to minimize the risk of exploitation. Avoid using the OSSEC HIDS agent to connect to untrusted or unknown UNC paths until the issue is resolved.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ossec Hids Agent For Windows