Executive brief
The WatchGuard Agent, a software component used for managing and monitoring Windows devices, contains a security flaw in its discovery service. An attacker on the same local network can exploit this to crash the agent service, leading to a denial-of-service condition. This prevents the agent from performing its management tasks and may disrupt security operations on the affected machine.
Technical details
A stack-based buffer overflow (CWE-121) exists in the WatchGuard Agent discovery service on Windows. The vulnerability is triggered when the service processes specially crafted discovery packets, leading to a memory corruption that crashes the process. An unauthenticated attacker located on the same adjacent network (Layer 2) can exploit this without user interaction. The primary impact is a denial-of-service (DoS) of the agent service. The issue is resolved in WatchGuard Agent version 1.25.03.0000.
Affected products
- WatchGuard Agent (Windows) up to and including 1.25.02.0000
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
- 2026-05-06: patched: Fixed in version 1.25.03.0000