Improper Access Control in Velociraptor's VQL Shell Feature
CVE-2025-0914

3.8LOW

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
27 February 2025

What is CVE-2025-0914?

An improper access control issue exists in the VQL shell feature of Velociraptor that permits authenticated users to execute the execve() plugin, even when this action has been explicitly restricted by setting the prevent_execve flag in the configuration file. This configuration setting is rarely recommended and typically not used, so the vulnerability is limited to deployments where it has been explicitly enabled. Users should upgrade to version 0.73.4 or later to mitigate this risk.

Affected Version(s)

Velociraptor 0 < 0.73.4

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Darragh O'Reilly, SUSE
.