CVE-2025-43079 describes a local privilege escalation vulnerability in the Qualys Cloud Agent's uninstall script for Mac and Linux. The script's reliance on an unsanitized $PATH environment and non-absolute paths allows an attacker with root/sudo privileges to execute arbitrary commands. This medium-severity vulnerability (CVSS 6.3) requires high privileges and user interaction, but could lead to full compromise of the system. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Qualys Inc | Qualys Agent | >= 3.12, < 7.1.0CNA affecteddefault affected | |
| Qualys Inc | Qualys Agent | >= 4.17, < 6.0.0CNA affecteddefault affected | |
| Qualys Inc | Qualys Agent | >= 0, < 6.2.1CNA affecteddefault unaffected | |
| Qualys Inc | Qualys Agent | >= 0, < 6.0.3CNA affecteddefault unaffected | |
| Qualys Inc | Qualys Agent | >= 0, < 5.0.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Local Privilege Escalation using qagent_uninstall.sh on Cloud Agent
Nov 11, 2025Local Privilege Escalation using qagent_uninstall.sh on Cloud Agent
Nov 11, 2025Local Privilege Escalation using qagent_uninstall.sh on Cloud Agent
Nov 11, 2025Local Privilege Escalation using qagent_uninstall.sh on Cloud Agent
Nov 11, 2025Local Privilege Escalation using qagent_uninstall.sh on Cloud Agent
Nov 11, 2025Local Privilege Escalation using qagent_uninstall.sh on Cloud Agent
Nov 11, 2025