PT-2025-44187 · Wazuh · Wazuh

Published

2025-10-28

·

Updated

2025-10-28

·

CVE-2025-34294

CVSS v4.0

7.1

High

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Wazuh (affected versions not specified)
Description A time-of-check/time-of-use (TOCTOU) race condition exists in the File Integrity Monitoring (FIM) component when automatic threat removal is enabled. This can allow a local, low-privileged attacker to cause the Wazuh service, running with SYSTEM privileges, to delete attacker-controlled files or paths. The issue stems from insufficient synchronization and a lack of final-path validation during the threat-removal process. Specifically, the agent records a threat removal action and proceeds with deletion without verifying the deletion target remains the originally intended file. This can lead to arbitrary file or folder deletion at the SYSTEM level, potentially resulting in local privilege escalation. An attempted fix was made via pull request 8697 on 2025-07-10, but it was incomplete.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16388
CVE-2025-34294

Affected Products

Wazuh