CVE-2025-6264

unknown
Published 2025-06-20 · Modified 2026-03-03
CVSS v3
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
CVSS v2
VIR risk

Description

Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-6264.html

OS impact

OSVersionStatusFixed in
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
golang Gowww.velocidex.com/golang/velociraptor<0.74.30.74.3

References

Verify integrity in audit chain (admin only). AS-IS.