Buffer Over-Read Vulnerability in Wazuh Platform by Wazuh Inc.
CVE-2025-62792
What is CVE-2025-62792?
The Wazuh platform is susceptible to a buffer over-read vulnerability that occurs within the function w_expression_match(). This issue arises due to improper NULL termination of a buffer during its allocation in OS_CleanMSG(), leading to the potential for a compromised agent to exploit this flaw. By sending a specially crafted message to the Wazuh manager, an attacker may cause a READ operation beyond the end of the allocated buffer, thereby gaining unauthorized access to sensitive information. This vulnerability has been rectified in version 4.12.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wazuh < 4.12.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
