CVE-2025-69784
A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an attacker-controlled DLL into high-privilege processes. This results in arbitrary code execution with SYSTEM privileges, leading to full compromise of the affected system.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- xcitium/openedr
- Source
- cve@mitre.org
References
- https://gist.github.com/ikerl/c3ec81f12ded44c2e0ae2dfdacb562baExploit
- https://github.com/ComodoSecurity/openedrProduct
- https://github.com/ComodoSecurity/openedr/issues/49Issue Tracking, Third Party Advisory
- https://scavengersecurity.com/posts/edr-as-rootkit-2/Exploit, Third Party Advisory
- https://www.openedr.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.