CVE-2025-30201

7.7

Wazuh · Wazuh Agent

A vulnerability in Wazuh Agent prior to 4.13.0 allows authenticated attackers to force NTLM authentication via malicious UNC paths, potentially leading to privilege escalation and remote code execution.

Executive summary

Wazuh Agent versions prior to 4.13.0 are vulnerable to NTLM relay attacks that can lead to remote code execution and privilege escalation.

Vulnerability

The vulnerability involves improper handling of file paths (CWE-73) within agent configuration settings, allowing an authenticated attacker with high privileges to trigger NTLM authentication requests via malicious UNC paths. This mechanism facilitates NTLM relay attacks, which can be leveraged to achieve remote code execution and escalate privileges within the affected environment.

Business impact

Successful exploitation of this vulnerability poses a severe risk to the integrity and confidentiality of the entire security monitoring infrastructure. Because Wazuh agents typically run with elevated permissions, a successful NTLM relay attack could allow an adversary to gain control over the agent host, potentially leading to full system compromise. Given the CVSS score of 7.7, this vulnerability represents a high-risk scenario that could facilitate lateral movement and unauthorized access to sensitive security data.

Remediation

Immediate Action: Upgrade all instances of Wazuh Agent to version 4.13.0 or later to apply the necessary security patches.

Proactive Monitoring: Monitor system logs for unusual UNC path configurations or unexpected authentication traffic originating from agent service accounts.

Compensating Controls: Restrict network access to prevent unauthorized SMB/NTLM traffic and enforce SMB signing or channel binding to mitigate the effectiveness of potential relay attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk to the security infrastructure due to its potential for remote code execution. Administrators should prioritize the deployment of version 4.13.0 across all managed endpoints to neutralize the underlying flaw. Given the existence of proof-of-concept material, failure to patch promptly could leave the environment susceptible to internal threat actors or compromised administrative accounts.

More Wazuh CVEs

Sources