- Description
- Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various agent configuration settings, potentially leading NTLM relay attacks that would result privilege escalation and remote code execution. This issue has been patched in version 4.13.0.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- wazuh
CVSS 3.1
- Type
- Primary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-73
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
SECURITY ALERT: CVE-2025-30201 Exploit Fix & Mitigation Guide Read more: https://t.co/ezkm7bAcvL #Cybersecurity #CVE https://t.co/WJJgrLgBb3
@SecReportCVE
19 Dec 2025
8 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔴 Wazuh, NTLM Relay Vulnerability, #CVE-2025-30201 (Critical) https://t.co/bOZ9F1jpfi
@dailycve
2 Dec 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-30201 NTLM Authentication Bypass in Wazuh Agent Before 4.13.0 Enables Privilege Escalation https://t.co/Pzc3bZW8cy
@VulmonFeeds
21 Nov 2025
41 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
CVE-2025-30201 Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authentic… https://t.co/X1koGY9kO8
@CVEnew
21 Nov 2025
288 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6248EA61-D178-48E6-B2E3-EA37BFEDC305",
"versionEndExcluding": "4.13.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]