CVE-2025-64996: Overly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin's output
In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mkinotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64996?
CVE-2025-64996 is considered to have a significant impact since it allows local users to read and manipulate sensitive plugin output.
How do I fix CVE-2025-64996?
To fix CVE-2025-64996, update Checkmk to version 2.4.0p16 or 2.3.0p41, or use a later version.
What versions are affected by CVE-2025-64996?
CVE-2025-64996 affects Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older.
What risks are associated with CVE-2025-64996?
The risks associated with CVE-2025-64996 include unauthorized access to sensitive information and potential manipulation of plugin data by local users.
Who is affected by CVE-2025-64996?
Any user of Checkmk versions prior to the specified updates is at risk from CVE-2025-64996 as it allows local users to exploit the vulnerability.