CVE-2025-69784

A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an attacker-controlled DLL into high-privilege processes. This results in arbitrary code execution with SYSTEM privileges, leading to full compromise of the affected system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xcitium:openedr:2.5.1.0:*:*:*:*:*:*:*

History

20 Mar 2026, 13:51

Type Values Removed Values Added
CPE cpe:2.3:a:xcitium:openedr:2.5.1.0:*:*:*:*:*:*:*
First Time Xcitium
Xcitium openedr
References () https://gist.github.com/ikerl/c3ec81f12ded44c2e0ae2dfdacb562ba - () https://gist.github.com/ikerl/c3ec81f12ded44c2e0ae2dfdacb562ba - Exploit
References () https://github.com/ComodoSecurity/openedr - () https://github.com/ComodoSecurity/openedr - Product
References () https://github.com/ComodoSecurity/openedr/issues/49 - () https://github.com/ComodoSecurity/openedr/issues/49 - Issue Tracking, Third Party Advisory
References () https://scavengersecurity.com/posts/edr-as-rootkit-2/ - () https://scavengersecurity.com/posts/edr-as-rootkit-2/ - Exploit, Third Party Advisory
References () https://www.openedr.com/ - () https://www.openedr.com/ - Product
Summary
  • (es) Un atacante local y no privilegiado puede abusar de una interfaz IOCTL vulnerable expuesta por el controlador del kernel OpenEDR 2.5.1.0 para modificar la ruta de inyección de DLL utilizada por el producto. Al redirigir esta ruta a una ubicación escribible por el usuario, un atacante puede hacer que OpenEDR cargue una DLL controlada por el atacante en procesos de alto privilegio. Esto resulta en ejecución de código arbitrario con privilegios de SYSTEM, lo que lleva a un compromiso total del sistema afectado.

16 Mar 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-427

16 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 16:16

Updated : 2026-03-20 13:51


NVD link : CVE-2025-69784

Mitre link : CVE-2025-69784

CVE.ORG link : CVE-2025-69784


JSON object : View

Products Affected

xcitium

  • openedr
CWE
CWE-427

Uncontrolled Search Path Element