PT-2025-47793 · Wazuh · Wazuh Agent
Published
2025-11-21
·
Updated
2025-12-02
·
CVE-2025-30201
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wazuh versions prior to 4.13.0
Description
Wazuh is a platform for threat prevention, detection, and response. A flaw in the Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC (Universal Naming Convention) paths in agent configuration settings. This can lead to NTLM relay attacks, where attackers capture and relay NTLM authentication hashes, potentially gaining unauthorized access and leading to privilege escalation and remote code execution. The vulnerability resides in the Security Configuration Assessment (SCA) module and involves improper external control of file names or paths. Exploitation involves the use of specially crafted UNC paths.
Recommendations
Upgrade to Wazuh Agent version 4.13.0 or later.
Exploit
Fix
LPE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wazuh Agent