CNNVD-202509-4275 Information
Sep 27, 2025
cve
CNNVD ID
CNNVD-202509-4275
Related CVE
- CNNVD Published: 2025-09-27
Description (Chinese)
Wazuh是Wazuh开源的一个应用软件。用于收集,汇总,索引和分析安全数据,帮助组织检测入侵,威胁和行为异常。 Wazuh 3.8.0版本至4.11.0之前版本存在安全漏洞,该漏洞源于解析Windows EventChannel消息中的XML元素时存在堆缓冲区溢出。
Description (English)
Wazuh is an application from the Wazuh Open Source. For collection, aggregation, indexing and analysis of security data to help the organization detect invasions, threats and behavioural anomalies. Wazuh 3.8.0 to 4.11.0 had a security loophole, which stemmed from the proliferation of buffer zones when the XML elements in Windows Event Channel were decrypted.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
Wazuh
Published
2025-09-27
Last Modified
2026-02-24
References
https://github.com/wazuh/wazuh/security/advisories/GHSA-vw3r-mjg3-9hh2 https://access.redhat.com/security/cve/cve-2025-59938
Patch
https://github.com/wazuh/wazuh/releases
Share on: