CVE Database
/

CVE-2025-43079

Back to search

CVE-2025-43079

Published: Nov 10, 2025

Modified: Mar 18, 2026

PUBLISHED

CVSS v3.1

6.3

MEDIUM

Description

The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using absolute paths and without sanitizing the $PATH environment. If the uninstall script is executed with elevated privileges (e.g., via sudo) in an environment where $PATH has been manipulated, an attacker with root/sudo privileges could cause malicious executables to be run in place of the intended system binaries. This behavior can be leveraged for local privilege escalation and arbitrary command execution under elevated privileges.

VendorProductVersions

Qualys Inc

Qualys Agent

affected
5.0 - < 7.2.3

Qualys Inc

Qualys Agent

affected
3.12 - < 7.1.0

Qualys Inc

Qualys Agent

affected
4.17 - < 6.0.0

Qualys Inc

Qualys Agent

affected
0 - < 6.2.1

Qualys Inc

Qualys Agent

affected
0 - < 6.3.1

Qualys Inc

Qualys Agent

affected
0 - < 3.31.1-8

Qualys Inc

Qualys Agent

affected
0 - < 3.21.1-6

Qualys Inc

Qualys Agent

affected
0 - < 4.2.6

Qualys Inc

Qualys Agent

affected
0 - < 5.0.3

Qualys Inc

Qualys Agent

affected
0 - < 5.0.2

Qualys Inc

Qualys Agent

affected
0 - < 6.0.3

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

High

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now