Critical Remote Code Execution Vulnerability in Wazuh – CVE-2025-24016

ISGroup Cybersecurity

Wazuh, a unified open-source XDR and SIEM platform, contains a critical vulnerability (CVE-2025-24016) affecting versions >= 4.4.0 and < 4.9.1. This issue, stemming from insecure deserialization, allows for Remote Code Execution (RCE) via malicious input to the DistributedAPI. Given its role as a core component in IT security monitoring, the exploitation of this vulnerability poses significant risks to the system’s integrity and availability.

The vulnerability has a CVSS score of 9.9 (Critical) and can be exploited by attackers with valid API credentials. If default credentials are still in use, they can be leveraged to compromise the system. Furthermore, a compromised Wazuh agent could serve as an entry point for the attack. This issue particularly impacts organizations that rely on Wazuh clusters or configurations where agents play key roles.

ProductWazuh
Date2025-02-18 12:36:09
Information
  • Trending
  • Fix Available

Technical Summary

CVE-2025-24016 stems from the insecure deserialization of DistributedAPI (DAPI) parameters treated as JSON objects. Specifically, the as_wazuh_object function in the Wazuh framework does not properly sanitize inputs. An attacker in possession of valid API credentials can inject a non-sanitized dictionary to exploit this vulnerability, leading to arbitrary Python code execution.

Exploitation Scenarios:

  1. API Access with valid credentials

    • The vulnerability can be triggered by sending a malicious request (e.g., via the run_as endpoint). An attacker with valid credentials can fully control the auth_context parameter, which is forwarded to the master server for processing.
    • Default credentials (e.g., wazuh-wui:MyS3cr37P450r.*-) significantly increase the risk if they are not changed.
    • Malicious payloads in such requests lead to RCE on the master server.
  2. Compromised Agent

    • A compromised agent can send a crafted getconfig response containing malicious JSON.
    • If this request propagates between servers in a cluster, it could cause insecure deserialization on the target server.

Technical details:

  • The vulnerability originates in the framework/wazuh/core/cluster/common.py file, where the as_wazuh_object function inadequately handles serialized JSON data.
  • Malicious JSON objects, including those with attributes like __unhandled_exc__, can execute arbitrary code.
  • Examples of abuse include injecting __callable__ objects or triggering exception gadgets to further compromise the system.

Recommendations

  1. Apply the patch immediately
  • Update to Wazuh 4.9.1 or later versions, where the vulnerability has been fully resolved. Apply this patch to all affected components, including servers and agents, following the testing and approval processes adopted by your organization.
  1. Change default credentials
  • Ensure that default credentials, such as wazuh-wui:MyS3cr37P450r.*-, are changed immediately. Use strong, unique passwords for all accounts to prevent unauthorized access.
  1. Improve monitoring
  • Implement logging and detection mechanisms to identify suspicious API requests, particularly toward endpoints like run_as or DAPI requests.
  • Monitor for anomalous agent behavior, such as unexpected getconfig responses.
  1. Input sanitization and configuration hardening
  • Ensure that all inputs reaching as_wazuh_object are properly validated.
  • Isolate critical components within the Wazuh architecture to limit exploitation paths (e.g., by separating agent communications from API access).

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert