Executive brief
A security vulnerability in the WatchGuard Agent for Windows could allow a local user to gain full administrative control over a computer. The software, which is used to manage and secure endpoints, contains a flaw that allows an attacker to inject and run unauthorized code. This could lead to a complete system takeover, allowing the attacker to access sensitive data or disable security protections.
Technical details
The WatchGuard Agent for Windows (versions prior to 1.25.03.0000) contains a hard-coded cryptographic key (CWE-321). This vulnerability allows a local attacker with low privileges to bypass security controls and inject code into existing agent processes. When chained with other service vulnerabilities, this can lead to local privilege escalation (LPE) to SYSTEM. The issue is resolved in version 1.25.03.0000. Attackers must have local access to the target machine to exploit this flaw.
Affected products
- WatchGuard WatchGuard Agent (Windows) before 1.25.03.0000
Timeline
- 2026-05-06: disclosed: Initial disclosure by WatchGuard
- 2026-05-06: patched: Fixed in version 1.25.03.0000
- 2026-05-06: advisory: WatchGuard advisory WGSA-2026-00013 published