CVE-2025-69783: High severity OpenEDR OpenEDR vulnerability

Published Mar 16, 2026
·
Updated

A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trusted process name (e.g., csrss.exe, edrsvc.exe, edrcon.exe). This allows unauthorized interaction with the OpenEDR kernel driver, granting access to privileged functionality such as configuration changes, process monitoring, and IOCTL communication that should be restricted to trusted components. While this issue alone does not directly grant SYSTEM privileges, it breaks OpenEDR's trust model and enables further exploitation leading to full local privilege escalation.

Affected Software

2 affected components
OpenEDR OpenEDR
Xcitium Openedr=2.5.1.0

Event History

Mar 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-69783?

CVE-2025-69783 is considered a high-severity vulnerability due to the potential for unauthorized access to privileged functionality.

2

How do I fix CVE-2025-69783?

To fix CVE-2025-69783, update OpenEDR to a version that addresses this vulnerability, ensuring that the self-defense mechanism is properly secured.

3

Who is affected by CVE-2025-69783?

CVE-2025-69783 affects users of OpenEDR version 2.5.1.0 who have not implemented protective measures against local exploitation.

4

Can CVE-2025-69783 be exploited remotely?

No, CVE-2025-69783 requires local access to successfully exploit the vulnerability by renaming a malicious executable.

5

What are the risks associated with CVE-2025-69783?

The risks associated with CVE-2025-69783 include potential unauthorized interaction with the OpenEDR kernel driver and access to sensitive system functions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203