CVE-2025-6264 | Velociraptor priviledge escalation via UpdateConfig artifact

Exp

Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions.  To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The Admin.Client.UpdateClientConfig is an artifact used to update the client's configuration. This artifact did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and update the configuration. This can lead to arbitrary command execution and endpoint takeover. To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the "Investigator' role).

Published: 2025-06-20 Last update: 2025-10-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2025-6264 is rated Exploit Available (55.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.28%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2025-6264

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2025-6264

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-04-16 0.05% 0.28% +0.22%
2 2026-01-14 0.04% 0.05% +0.01%
3 2025-11-21 0.04%

Full EPSS history (14 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-6264

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.5 3.1 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:H)
They need powerful rights—admin, root, or similar—before this pays off.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:L)
Might cause slowdowns, glitches, or partial disruption—not a full brick.
1.3 3.7 [email protected]

Weakness enumeration for CVE-2025-6264

GitHub Security Advisory for CVE-2025-6264

GHSA-gpfc-mph4-qm24 · Severity: medium · Ecosystem: go — Velociraptor vulnerable to privilege escalation via UpdateConfig artifact

OS Trackers for CVE-2025-6264

vendor priority summary link
suse medium https://www.suse.com/security/cve/CVE-2025-6264/

Affected software / configurations for CVE-2025-6264

Vendor Product Version Raw CPE
rapid7 velociraptor < 0.74.3 cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:*

References for CVE-2025-6264

cvelogic Threat Intelligence