Improper Input Validation in OSSEC HIDS Agent for Windows
CVE-2024-1244
What is CVE-2024-1244?
The OSSEC HIDS Agent for Windows prior to version 3.8.0 is susceptible to improper input validation. An attacker capable of controlling the OSSEC server or possessing the agent's key can manipulate the agent's configuration to connect to a malicious UNC path. This vulnerability can lead to the exposure of machine account NetNTLMv2 hashes. Such compromises enable attackers to relay these hashes to perform remote code execution or escalate privileges to SYSTEM by means of Active Directory Certificate Services (AD CS) certificate forging and similar methods.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OSSEC-HIDS Agent Windows 3.8.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
