CVE-2025-69783 affects OpenEDR version 2.5.1.0, allowing a local attacker to bypass its self-defense mechanism by renaming a malicious executable to a trusted process name. This bypass grants unauthorized access to the OpenEDR kernel driver's privileged functionality, breaking its trust model and enabling further local privilege escalation. The vulnerability is rated High severity (CVSS 7.8), requiring local access with low privileges and no user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5.1.0CPE matchmatch criteria | cpe:2.3:a:xcitium:openedr:2.5.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.