CVE-2025-32919: Privilege Escalation in Windows License plugin for Checkmk Windows Agent
Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all versions of 2.1.0 (EOL).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32919?
CVE-2025-32919 is classified as a high-severity vulnerability due to its potential for Privilege Escalation.
How do I fix CVE-2025-32919?
To fix CVE-2025-32919, update the Checkmk Windows Agent to version 2.4.0p13 or newer, 2.3.0p38 or newer, or 2.2.0p46 or newer.
Which versions of Checkmk are affected by CVE-2025-32919?
CVE-2025-32919 affects Checkmk versions from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all versions of 2.1.0.
What type of vulnerability is CVE-2025-32919?
CVE-2025-32919 is a Privilege Escalation vulnerability caused by the use of an insecure temporary directory.
Who is the vendor of the software affected by CVE-2025-32919?
The vendor of the affected software is Checkmk.