PT-2025-39698 · Wazuh · Wazuh

Published

2025-09-26

·

Updated

2025-10-16

·

CVE-2025-59938

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wazuh versions 3.8.0 through 4.10.9
Description Wazuh, a platform for threat prevention, detection, and response, contains a heap buffer overflow in the wazuh-analysisd component. This issue occurs when parsing XML elements received from Windows EventChannel messages.
Recommendations Update to version 4.11.0 or later.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-14831
CVE-2025-59938
GHSA-VW3R-MJG3-9HH2

Affected Products

Wazuh