Impact
Use of hard‑coded cryptographic key vulnerability in WatchGuard Agent on Windows allows inclusion of code in an existing process. This flaw permits code execution with the privileges that the agent runs under and is classified as CWE‑321, indicating insecure key management.
Affected Systems
Versions of WatchGuard Agent for Windows that are older than 1.25.03.0000 are affected. All installations of the single WatchGuard Agent product distributed by WatchGuard prior to this release are susceptible.
Risk and Exploitability
The CVSS score of 8.5 reflects a high severity vulnerability. The EPSS score is reported as <1%, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves delivering a specially crafted payload that abuses the hard‑coded cryptographic key to bypass integrity checks; the attack could be local or remote, depending on the agent’s network exposure. The exploitation would require the attacker to gain access to the agent’s input channel.
OpenCVE Enrichment