CVE-2025-69784
A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an attacker-controlled DLL into high-privilege processes. This results in arbitrary code execution with SYSTEM privileges, leading to full compromise of the affected system.
Published:Mar 16, 2026
Last Modified:Mar 23, 2026
EPS:Mar 16, 2026
EPSS Score:0.00018
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Comodosecurity
Product
Openedr
Comodosecurity
Openedr
Vendor
Xcitium
Product
Openedr
Xcitium
Openedr
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
