CVE-2025-53841 Details
Description
The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows users have default write access to. This allows an unprivileged local user to create a crafted "openssl.cnf" file in that location and, by specifying the path to a custom DLL file in a custom OpenSSL engine definition, execute arbitrary commands with the privileges of the Guardicore Agent process. Since Guardicore Agent runs with SYSTEM privileges, this permits an unprivileged user to fully elevate privileges to SYSTEM level in this manner.
A local privilege escalation vulnerability has been identified in the Akamai Guardicore Platform Agent, affecting versions prior to 50.15.0, 51.12.0, and 52.1.1. This vulnerability allows an unprivileged user to elevate privileges to SYSTEM, the highest level on Windows systems.
Akamai has released patches for all affected versions. Users can download the latest version through the Akamai Control Center, or contact their Akamai account representative for assistance.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 3, 2025CISA-ADP
Assessed Dec 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Akamai Guardicore Platform Agent | < 50.15.0 (semver) < 51.12.0 (semver) < 52.1.1 (semver) |
CPE
Remediation
| |
| Microsoft Remote Desktop Multimedia Redirection Service | All versions |
CPE
Remediation
| |
| NCP Secure Enterprise Client Suite | All versions |
CPE
Remediation
| |
| Tenable Nessus Agent | All versions |
CPE
Remediation
| |
| Windows SDK | All versions |
CPE
Remediation
| |
| Dradis | All versions |
CPE
Remediation
| |
| Fortinet FortiExtender Application | All versions |
CPE
Remediation
| |
| DATEV Personal-Managementsystem comfort/comfort plus | All versions |
CPE
Remediation
| |
| Dassault Systèmes ENOVIA V6 | All versions |
CPE
Remediation
| |
| baramundi Management Agent | All versions |
CPE
Remediation
| |
| Trend Micro Apex One | All versions |
CPE
Remediation
| |
| otris Update Manager | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | CVE Modified | [email protected] |
| Dec 5, 2025 | CVE Modified | [email protected] |
| Dec 3, 2025 | New CVE Received | [email protected] |
Volerion