Security advisory for CVE-2025-67900 affecting NXLog Agent 6.10 and older on Windows
We are committed to the security of our customers, and wish to inform you of CVE-2025-67900, a recently published vulnerability affecting the Windows version of NXLog Agent 6.10 and older.
Technical description The Windows version of NXLog Agent 6.10.10368 and older includes a Privilege Escalation vulnerability because it attempts to load an OpenSSL configuration file from the hardcoded and unintended directory C:\nxlog4\x64\ on startup.
This is a legacy installation directory that may not exist in clean NXLog Agent installations.