CVE-2025-43079: Local Privilege Escalation via qagent_uninstall.sh Qualys Cloud Agents
The Qualys Cloud Agent included a bundled uninstall script (qagentuninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using absolute paths and without sanitizing the $PATH environment. If the uninstall script is executed with elevated privileges (e.g., via sudo) in an environment where $PATH has been manipulated, an attacker with root/sudo privileges could cause malicious executables to be run in place of the intended system binaries. This behavior can be leveraged for local privilege escalation and arbitrary command execution under elevated privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43079?
CVE-2025-43079 has been classified as a high severity vulnerability due to its potential to execute arbitrary commands.
How do I fix CVE-2025-43079?
To fix CVE-2025-43079, users should update the Qualys Cloud Agent to the latest version available that addresses this vulnerability.
What systems are affected by CVE-2025-43079?
CVE-2025-43079 affects the Qualys Cloud Agent on MacOS and Linux versions.
What can happen if CVE-2025-43079 is exploited?
If exploited, CVE-2025-43079 could allow an attacker to execute arbitrary system commands, potentially compromising the system.
Is there a workaround for CVE-2025-43079?
As a workaround for CVE-2025-43079, users can manually avoid executing the uninstall script until an official patch is applied.