Bypass Vulnerability in OpenEDR Self-Defense Mechanism by Comodo
CVE-2025-69783
7.8HIGH
What is CVE-2025-69783?
A local attacker can circumvent the self-defense mechanism of OpenEDR version 2.5.1.0 by renaming a malicious executable to impersonate a trusted process such as csrss.exe, edrsvc.exe, or edrcon.exe. This manipulation can result in unauthorized access to the OpenEDR kernel driver, thereby allowing modifications to configurations, monitoring of processes, and IOCTL communication. Although this vulnerability does not directly confer SYSTEM privileges, it undermines the integrity of OpenEDR's trust model, opening pathways for further exploits that may facilitate complete local privilege escalation.
