CVE-2025-34294: Wazuh File Integrity Monitoring (FIM) & Active Response Arbitrary File Deletion as SYSTEM
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the behavior originates from a documentation-published Active Response example script. Please refer to this advisory ( https://github.com/wazuh/wazuh-documentation/security/advisories/GHSA-46r5-xp98-fpgg ) for further information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34294?
CVE-2025-34294 has been classified as a high severity vulnerability due to its potential for local exploitation by low-privileged attackers.
How do I fix CVE-2025-34294?
To mitigate CVE-2025-34294, you should disable automatic threat removal in Wazuh's File Integrity Monitoring configuration.
What types of attackers can exploit CVE-2025-34294?
CVE-2025-34294 can be exploited by local, low-privileged attackers who can manipulate the time-of-check/time-of-use conditions.
Which software is affected by CVE-2025-34294?
CVE-2025-34294 specifically affects Wazuh's File Integrity Monitoring component.
What is the nature of the vulnerability in CVE-2025-34294?
CVE-2025-34294 is a time-of-check/time-of-use (TOCTOU) race condition that can be exploited to delete files by the Wazuh service running with elevated privileges.