CVE Explorer
CVE-2025-62786
Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds WRITE occurs in decode_win_permissions, resulting in writing a NULL byte 2 bytes before the start of the buffer allocated to decoded_it. A compromised agent can potentially leverage this issue to perform remote code execution, by sending a specially crafted message to the wazuh manager. An attacker who is able to craft and send an agent message to the wazuh manager can leverag
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"wazuh","vendor":"wazuh","versions":[{"status":"affected","version":"< 4.10.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:49d94aed1791ded5dda8912c3e6c51fa314bddf055c46bdaf5bedc550a31c442 · sha256:ebbb284bea64b959… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:49d94aed1791ded5dda8912c3e6c51fa314bddf055c46bdaf5bedc550a31c442 · sha256:ebbb284bea64b959… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-124","description":"CWE-124: Buffer Underwrite ('Buffer Underflow')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:49d94aed1791ded5dda8912c3e6c51fa314bddf055c46bdaf5bedc550a31c442 · sha256:ebbb284bea64b959… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/wazuh/wazuh/commit/2257d7998aaff34263169d16f4afc491564a771c","tags":["x_refsource_MISC"],"url":"https://github.com/wazuh/wazuh/commit/2257d7998aaff34263169d16f4afc491564a771c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49d94aed1791ded5dda8912c3e6c51fa314bddf055c46bdaf5bedc550a31c442 · sha256:ebbb284bea64b959… · /containers/cna/references/1
{"name":"https://github.com/wazuh/wazuh/security/advisories/GHSA-2c8r-p6r5-xxmr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/wazuh/wazuh/security/advisories/GHSA-2c8r-p6r5-xxmr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49d94aed1791ded5dda8912c3e6c51fa314bddf055c46bdaf5bedc550a31c442 · sha256:ebbb284bea64b959… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.