CVE-2025-62786 Details
Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds WRITE occurs in decode_win_permissions, resulting in writing a NULL byte 2 bytes before the start of the buffer allocated to decoded_it. A compromised agent can potentially leverage this issue to perform remote code execution, by sending a specially crafted message to the wazuh manager. An attacker who is able to craft and send an agent message to the wazuh manager can leverage this issue to potentially achieve remote code execution on the wazuh manager (the exploitability of this vulnerability depends on the specifics of the respective heap allocator). This vulnerability is fixed in 4.10.2.
A heap-based buffer underflow vulnerability has been identified in Wazuh versions through 4.10.1. The issue occurs in the decode_win_permissions function, where a NULL byte is written two bytes before the start of an allocated buffer. This vulnerability can be exploited by a compromised agent that sends a specially crafted message to the Wazuh manager, potentially leading to remote code execution. The exploitability of this vulnerability depends on the specifics of the heap allocator.
Users can upgrade to Wazuh version 4.10.2 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/wazuh/wazuh/commit/2257d7998aaff34263169d16f4afc491564a771c | [email protected] | Patch |
| https://github.com/wazuh/wazuh/security/advisories/GHSA-2c8r-p6r5-xxmr | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-124 | Buffer Underwrite ('Buffer Underflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wazuh wazuh | < 4.10.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | Initial Analysis | [email protected] |
| Oct 29, 2025 | New CVE Received | [email protected] |