CVE-2025-6264: Rapid7 Velociraptor Incorrect Default Permissions Vulnerability

Published Jun 20, 2025
·
Updated

Rapid7 Velociraptor contains an incorrect default permissions vulnerability that can lead to arbitrary command execution and endpoint takeover. To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint.

Other sources

Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions.  To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch.

The Admin.Client.UpdateClientConfig is an artifact used to update the client's configuration. This artifact did not enforce an additional required permission, allowing users with COLLECTCLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and update the configuration.

This can lead to arbitrary command execution and endpoint takeover.

To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECTCLIENT given typically by the "Investigator' role).

GitHub

Affected Software

3 affected componentsFixes available
go/www.velocidex.com/golang/velociraptor<0.74.3
0.74.3
Rapid7 Velociraptor
Rapid7 Velociraptor<0.74.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/www.velocidex.com/golang/velociraptor to a version that resolves this vulnerability.

    Fixed in 0.74.3

Event History

Jun 20, 2025
CVE Published
via MITRE·02:01 AM
Data Sourced
via MITRE·02:01 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 AM
Data Sourced
via GitHub·03:30 AM
DescriptionSeverityWeaknessAffected Software
Oct 9, 2025
News Published
via BleepingComputer·07:31 PM
News Published
via BleepingComputer·07:32 PM
Oct 14, 2025
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-6264?

CVE-2025-6264 is considered a high severity vulnerability due to the potential for elevated permissions and unrestricted access to sensitive artifacts.

2

How do I fix CVE-2025-6264?

To remediate CVE-2025-6264, ensure your Velociraptor version is updated to 0.74.4 or later to mitigate the risks associated with artifact permissions.

3

What systems are affected by CVE-2025-6264?

CVE-2025-6264 affects Velociraptor versions up to and including 0.74.3.

4

What risks does CVE-2025-6264 pose?

CVE-2025-6264 allows unauthorized execution of potentially harmful VQL queries with elevated permissions, which can compromise system integrity and security.

5

Who can exploit CVE-2025-6264?

CVE-2025-6264 can be exploited by any user with access to the Velociraptor platform and the knowledge to execute malicious VQL queries.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203