CVE-2025-69784: High severity OpenEDR OpenEDR vulnerability
A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an attacker-controlled DLL into high-privilege processes. This results in arbitrary code execution with SYSTEM privileges, leading to full compromise of the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69784?
CVE-2025-69784 is rated as a high-severity vulnerability due to its potential for local exploitation and DLL hijacking.
How do I fix CVE-2025-69784?
To mitigate CVE-2025-69784, users should update OpenEDR to version 2.5.1.1 or higher, where the vulnerability has been addressed.
Who is affected by CVE-2025-69784?
CVE-2025-69784 affects users of OpenEDR version 2.5.1.0, specifically those with access to its vulnerable IOCTL interface.
What kind of attack can exploit CVE-2025-69784?
CVE-2025-69784 allows a local, non-privileged attacker to redirect the DLL injection path and load a malicious DLL.
Is there a workaround for CVE-2025-69784?
Temporary workarounds for CVE-2025-69784 include restricting access to the IOCTL interface until an update can be applied.