Wazuh wazuh-agent
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*
- >= 2.1.0, < 4.8.0
A vulnerability allowing shell injection has been identified in Wazuh's logcollector, maild, and Kaspersky AR script components, in both the Wazuh agent and manager, versions 2.1.0 prior to 4.8.0. This vulnerability allows attackers to execute arbitrary commands by injecting malicious scripts through configuration files, SMTP server settings, and custom flags, leading to remote code execution on the affected system.
Exploitation of this vulnerability allows for arbitrary command execution on the affected system, potentially leading to full system compromise.
The vulnerability can be reproduced by injecting malicious commands into Wazuh's configuration files or through the SMTP server settings when maild is running in local server mode. For example, after configuring maild to execute commands via the SMTP server tag, Wazuh can be restarted to trigger the command execution. Similarly, the Kaspersky AR script vulnerability can be exploited by injecting commands through the 'extra_args' parameter with the '--custom_flags' flag.
Users are advised to update Wazuh to version 4.8.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.