PT-2025-46696 · Datadog · Datadog-Agent+1

Published

2025-11-12

·

Updated

2025-11-12

·

CVE-2025-61667

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Datadog Agent versions 7.65.0 through 7.70.2
Description The Datadog Agent gathers events and metrics from hosts and transmits them to Datadog. A security issue exists in the Datadog Linux Host Agent due to inadequate permissions configured on the opt/datadog-agent/python-scripts/ pycache directory during installation. This directory’s contents are executed solely by the Agent during installation or upgrades. An attacker with local access could potentially modify files within this directory, leading to local privilege escalation when the Agent is upgraded. This requires local access to the host and a valid low privilege account. The vulnerability only affects the Linux Host Agent; other Agent variations, including those for containers, Kubernetes, and Windows hosts, are not impacted.
Recommendations Upgrade to Datadog Agent version 7.71.0 or later.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-61667
GHSA-6852-76C5-6CMG

Affected Products

Datadog-Agent
Datadog Linux Host Agent