CVE-2024-32038: Wazuh

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow hazard in wazuh-analysisd when handling Unicode characters from Windows Eventchannel messages. It impacts Wazuh Manager 3.8.0 and above. This vulnerability is fixed in Wazuh Manager 4.7.2.

Affected products

  • Wazuh Wazuh: from 3.8.0, before 4.7.2 (fixed in 4.7.2)

Published 2024-04-19. Last modified 2026-06-17.