Wazuh
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*
- >= 3.8.0, < 4.11.0
A heap buffer overflow vulnerability has been identified in Wazuh versions 3.8.0 prior to 4.11.0. The issue arises in the 'wazuh-analysisd' component when it processes XML elements from Windows EventChannel messages. This vulnerability can lead to a denial-of-service condition and an out-of-bounds read, causing the application to crash.
Exploitation of this vulnerability causes a segmentation fault, leading to a denial-of-service condition. The AddressSanitizer report indicates a heap buffer overflow, which is a common vulnerability type that can be exploited to execute arbitrary code or cause a crash.
The vulnerability can be reproduced by starting the 'wazuh-analysisd' service with the '-f' flag, which runs the service in the foreground. After the service is running, a crafted XML input file can be sent through the Unix domain socket used by Wazuh to queue event messages. This input triggers the heap buffer overflow, causing 'wazuh-analysisd' to crash with a segmentation fault.
Users can upgrade to Wazuh version 4.11.0 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.