Executive brief
A security vulnerability exists in the WatchGuard Agent for Windows, a software component used for managing and securing endpoint devices. An attacker who already has basic access to a computer can exploit incorrect file or resource permissions to gain full administrative control (SYSTEM privileges). This could allow an unauthorized user to bypass security controls, access sensitive data, or disrupt business operations on the affected machine.
Technical details
The vulnerability is classified as an Incorrect Permission Assignment for a Critical Resource (CWE-732) within the patch management component of the WatchGuard Agent on Windows. A local attacker with low-level authenticated access can exploit these weak permissions to modify or interact with sensitive resources used by the agent. Successful exploitation allows the attacker to escalate their privileges to NT AUTHORITY\SYSTEM, the highest level of access on a Windows system. The issue is resolved in WatchGuard Agent version 1.25.03.0000.
Affected products
- WatchGuard Agent versions up to (excluding) 1.25.03.0000
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
- 2026-05-11: patched: NVD updated with patch version information