Velociraptor Shell Plugin Prevent_execve Bypass
CVE-2025-0914

3.8LOW

Key Information:

Vendor
Rapid7
Status
Velociraptor
Vendor
CVE Published:
27 February 2025

Summary

An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users to execute the execve() plugin in deployments where this was explicitly forbidden by configuring the prevent_execve flag in the configuration file. This setting is not usually recommended and is uncommonly used, so this issue will only affect users who do set it. This issue is fixed in release 0.73.4.

Affected Version(s)

Velociraptor 0 < 0.73.4

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Darragh O'Reilly, SUSE
.