Heap-based Out-of-Bounds WRITE Vulnerability in Wazuh
CVE-2025-62786
6.3MEDIUM
What is CVE-2025-62786?
A heap-based out-of-bounds WRITE vulnerability exists in Wazuh, a popular open-source platform for threat detection and response. This vulnerability occurs in the decode_win_permissions function, where a NULL byte can be written two bytes before the beginning of an allocated buffer due to improper memory handling. An attacker with access to a compromised agent can exploit this flaw by crafting and sending a specially designed message to the Wazuh manager, potentially leading to remote code execution. The seriousness of this vulnerability hinges on the characteristics of the specific heap allocator in use. It has been addressed and mitigated in Wazuh version 4.10.2.
Affected Version(s)
wazuh < 4.10.2
