CVE-2025-69783: High severity OpenEDR OpenEDR vulnerability
A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trusted process name (e.g., csrss.exe, edrsvc.exe, edrcon.exe). This allows unauthorized interaction with the OpenEDR kernel driver, granting access to privileged functionality such as configuration changes, process monitoring, and IOCTL communication that should be restricted to trusted components. While this issue alone does not directly grant SYSTEM privileges, it breaks OpenEDR's trust model and enables further exploitation leading to full local privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69783?
CVE-2025-69783 is considered a high-severity vulnerability due to the potential for unauthorized access to privileged functionality.
How do I fix CVE-2025-69783?
To fix CVE-2025-69783, update OpenEDR to a version that addresses this vulnerability, ensuring that the self-defense mechanism is properly secured.
Who is affected by CVE-2025-69783?
CVE-2025-69783 affects users of OpenEDR version 2.5.1.0 who have not implemented protective measures against local exploitation.
Can CVE-2025-69783 be exploited remotely?
No, CVE-2025-69783 requires local access to successfully exploit the vulnerability by renaming a malicious executable.
What are the risks associated with CVE-2025-69783?
The risks associated with CVE-2025-69783 include potential unauthorized interaction with the OpenEDR kernel driver and access to sensitive system functions.