Akamai acquires LayerX, delivering end-to-end security and real-time AI usage control to any browser. Get details

CVE-2025-53841: Guardicore Local Privilege Escalation Vulnerability

Akamai Wave Blue

Dec 09, 2025

Akamai InfoSec

Akamai Wave Blue

Written by

Akamai InfoSec

Share

Akamai has mitigated a local privilege escalation vulnerability in Akamai’s Guardicore Platform Agent for Windows. Updated versions containing a fix for this vulnerability have been available to all customers using Guardicore since the beginning of November 2025 and we are strongly encouraging all users to upgrade (if they have not yet done so).

Vulnerability details

The GC-AGENTS-SERVICE running as part of Akamai’s Guardicore Platform Agent on Windows was affected by a local privilege escalation vulnerability. The service attempted to read an OpenSSL configuration file from a nonexistent location that standard Windows users have default write access to. 

This allowed an unprivileged local user to create a crafted “openssl.cnf” file in that location and, by specifying the path to a custom DLL file in a custom OpenSSL engine definition, execute arbitrary commands with the privileges of the Guardicore Agent process. 

Since Guardicore Agent runs with SYSTEM privileges, this permitted an unprivileged user to fully elevate privileges to SYSTEM level in this manner.

This attack vector could only be exploited by a user with local access to the workstation or server; it is not remotely exploitable.

The vulnerability has been assigned CVE-2025-53841.

Mitigation

For upgrade instructions and version details, please see our Knowledge Base article or reach out to us via the Akamai Control Center Portal with any questions.

Special thanks

This vulnerability was brought to our attention by Shadi Habbal from TÜV Rheinland i-sec GmbH. Akamai would like to thank Shadi and TÜV Rheinland for their professional cooperation and responsible disclosure.

Akamai Wave Blue

Dec 09, 2025

Akamai InfoSec

Akamai Wave Blue

Written by

Akamai InfoSec

Tags

Share

Related Blog Posts

Security
Akamai Blog | Adding Multi-Factor Authentication to Employee Logins: A Sound Security Principle
February 22, 2022
The year 2021 was definitely challenging for security practitioners. The number of data breaches continued to rise; a report issued by the Identity Theft Resource Center stated that the total number of breaches in the first three quarters of 2021 exceeded the total number of events in all of 2020 by 17%.
Security
Akamai Blog | Why FIDO2 is the Answer to Better Security
May 21, 2021
A groundbreaking increase in security incidents is affecting governments around the world. In light of this, the United States issued a formal order to implement a robust set of security measures designed to improve the security of federal systems. In his most recent executive order, President Biden acknowledged that the United States and many other governments around the world are facing increasing malicious cyberattacks. In order to prevent, and recover from security incidents, the President is pushing to significantly improve the government's security stack, including the implementation of multi-factor authentication (MFA). In this post, I'll discuss how the government's plan to leverage MFA could be even better.
Security
PQC Migration Now Has a Deadline. Does Your DNS Estate?
July 23, 2026
Learn why crypto-agility depends not just on adopting the right standards, but on maintaining a clear, unified view of your DNS environment before the migration begins.