PT-2025-44187 · Wazuh · Wazuh
Published
2025-10-28
·
Updated
2025-10-28
·
CVE-2025-34294
CVSS v4.0
7.1
High
| Vector | AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Wazuh (affected versions not specified)
Description
A time-of-check/time-of-use (TOCTOU) race condition exists in the File Integrity Monitoring (FIM) component when automatic threat removal is enabled. This can allow a local, low-privileged attacker to cause the Wazuh service, running with SYSTEM privileges, to delete attacker-controlled files or paths. The issue stems from insufficient synchronization and a lack of final-path validation during the threat-removal process. Specifically, the agent records a threat removal action and proceeds with deletion without verifying the deletion target remains the originally intended file. This can lead to arbitrary file or folder deletion at the SYSTEM level, potentially resulting in local privilege escalation. An attempted fix was made via pull request 8697 on 2025-07-10, but it was incomplete.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wazuh