PT-2026-60610 · Wazuh · Wazuh
CVE-2026-40106
·
Published
2026-07-16
·
Updated
2026-07-20
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wazuh versions 4.6.0 through 4.14.4
Description
A heap-based buffer overflow exists in the syscheck component of the Wazuh agent for Windows. The issue occurs when the agent expands registry paths containing wildcards (* or ?), as it allocates a fixed-size heap buffer of 256 bytes. A low-privileged local attacker can trigger an out-of-bounds write during string concatenation by creating a registry subkey with the maximum allowed length of 255 characters within a monitored path. Because the wazuh-agent.exe process runs with NT AUTHORITYSYSTEM privileges, this can result in a silent Denial of Service or Local Privilege Escalation (LPE), which is the act of gaining higher-level permissions on a system.
Recommendations
Update to version 4.14.5.
Exploit
Fix
LPE
DoS
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wazuh