PT-2025-51276 · Dynatrace · Dynatrace Oneagent
Published
2025-12-15
·
Updated
2025-12-21
·
CVE-2025-65176
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dynatrace OneAgent versions prior to 1.325.47
Description
An issue exists in Dynatrace OneAgent where, when attempting to access a remote network share and receiving a "STATUS LOGON FAILURE" error, the agent retrieves all user tokens from the machine and repeatedly attempts network share access while impersonating those users. This can allow an unprivileged attacker with system access to perform NTLM relay attacks.
Recommendations
Update Dynatrace OneAgent to version 1.325.47 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dynatrace Oneagent