News and blog
NXLog main page
  • Products
    NXLog Platform
    Log collection
    Log management and analytics
    Log storage
    NXLog Community Edition
    Integrations
    Professional Services
  • Solutions
    Use cases
    Specific OS support
    SCADA/ICS
    Windows event log
    DNS logging
    MacOS logging
    Open Telemetry
    Solutions by industry
    Financial Services
    Government & Education
    Entertainment & Gambling
    Telecommunications
    Medical & Healthcare
    Military & Defense
    Law Firms & Legal Counsel
    Industrial & Manufacturing
  • Pricing
    Licensing
    Plans
  • Partners
    Find a Reseller
    Partner Program
    Partner Portal
  • Resources
    Documentation
    Blog
    White papers
    Videos
    Webinars
    Case Studies
    Community Program
    Community Forum
  • About
    Company
    Careers
  • Support
    Support portals
    Contact us

NXLog Platform
Log collection
Log management and analytics
Log storage
NXLog Community Edition
Integrations
Professional Services

Use Cases
Specific OS support
SCADA/ICS
Windows event log
DNS logging
MacOS logging
Open Telemetry
Solutions by industry
Financial Services
Government & Education
Entertainment & Gambling
Telecommunications
Medical & Healthcare
Military & Defense
Law Firms & Legal Counsel
Industrial & Manufacturing

Licensing
Plans

Find a Reseller
Partner Program
Partner Portal

Documentation
Blog
White papers
Videos
Webinars
Case Studies
Community Program
Community Forum

Company
Careers

Support portals
Contact us
Let's Talk
  • Start free
  • Interactive demo
Let's Talk
  • Start free
  • Interactive demo
NXLog search
  • Loading...
Let's Talk
  • Start free
  • Interactive demo
December 18, 2025 security

Security advisory for CVE-2025-67900 affecting NXLog Agent 6.10 and older on Windows

By Andrei Popa

Share
ALL ANNOUNCEMENT COMPARISON COMPLIANCE DEPLOYMENT SECURITY SIEM STRATEGY RSS

We are committed to the security of our customers, and wish to inform you of CVE-2025-67900, a recently published vulnerability affecting the Windows version of NXLog Agent 6.10 and older.

Technical description

The Windows version of NXLog Agent 6.10.10368 and older includes a Privilege Escalation vulnerability because it attempts to load an OpenSSL configuration file from the hardcoded and unintended directory C:\nxlog4\x64\ on startup.

This is a legacy installation directory that may not exist in clean NXLog Agent installations. Because standard Windows users can create directories under the filesystem root by default, a non-privileged attacker may create a malicious openssl.cnf file within that directory and cause the NXLog Agent process, which runs as NT AUTHORITY\SYSTEM, to load an unintended DLL and execute arbitrary code.

NXLog Agent 6.11 patches the vulnerability by removing the hardcoded path, thus eliminating the possibility of an attacker supplying an arbitrary OpenSSL configuration file and preventing unintended DLL loading.

The following timeline lists the relevant CVE events:

  • November 14, 2025: The Offensive Security Center from Deloitte France reported the vulnerability to NXLog.

  • December 2, 2025: NXLog Agent 6.11 was released including the security patch.

  • December 14, 2025: CVE-2025-67900 published in the NVD.

  • December 15, 2025: CVE record last modified.

Resolution

We strongly recommend upgrading to NXLog Agent 6.11, which addresses the vulnerability.

Mitigation workaround

If you cannot upgrade NXLog Agent immediately, consider implementing the following mitigation strategy on Windows hosts running NXLog Agent:

  1. Explicitly clear the OPENSSL_CONF environment variable to prevent loading untrusted configuration files from the filesystem. To do this, open Command Prompt as Administrator and run:

    setx OPENSSL_CONF "" /m
  2. Restart the nxlog service.

Additionally, we recommend following the instructions on Hardening NXLog Agent on Windows to configure a dedicated service account for running NXLog Agent.

Credits

We would like to thank Antoine Dubrana and Rémi Guillon Bony from Deloitte France’s Offensive Security Center for discovering and responsibly disclosing this vulnerability.

Further information

  • CVE-2025-67900 on NVD

  • NXLog Agent 6.11 release notes

If you have any questions or require assistance, please contact our support team. Thank you for your continued trust in NXLog.

NXLog Platform is an on-premises solution for centralized log management with
versatile processing forming the backbone of security monitoring.

With our industry-leading expertise in log collection and agent management, we comprehensively
address your security log-related tasks, including collection, parsing, processing, enrichment, storage, management, and analytics.

Start free Contact us
Share

Facebook Twitter LinkedIn Reddit Mail
Related Posts

The CrowdStrike incident and how the NXLog agent operates
5 minutes | July 25, 2024
Current challenges in log and telemetry data management
8 minutes | June 24, 2025
From NXLog Community Edition to NXLog Platform
4 minutes | May 13, 2025

Stay connected:

Sign up

Keep up to date with our monthly digest of articles.

By clicking singing up, I agree to the use of my personal data in accordance with NXLog Privacy Policy.

Featured posts

Security dashboards go dark: why visibility isn't optional, even when your defenses keep running
February 26, 2026
Building a practical OpenTelemetry pipeline with NXLog Platform
February 25, 2026
Announcing NXLog Platform 1.11
February 23, 2026
Adopting OpenTelemetry without changing your applications
February 10, 2026
Linux security monitoring with NXLog Platform: Extracting key events for better monitoring
January 9, 2026
2025 and NXLog - a recap
December 18, 2025
Announcing NXLog Platform 1.10
December 11, 2025
Announcing NXLog Platform 1.9
October 22, 2025
Gaining valuable host performance metrics with NXLog Platform
September 30, 2025
Security Event Logs: Importance, best practices, and management
July 22, 2025
Enhancing security with Microsoft's Expanded Cloud Logs
June 10, 2025

Categories

  • ANNOUNCEMENT
  • COMPARISON
  • COMPLIANCE
  • DEPLOYMENT
  • SECURITY
  • SIEM
  • STRATEGY
  • Products
  • NXLog Platform
  • NXLog Community Edition
  • Integration
  • Professional Services
  • Licensing
  • Plans
  • Resources
  • Documentation
  • Blog
  • White Papers
  • Videos
  • Webinars
  • Case Studies
  • Community Program
  • Community Forum
  • Compare NXLog Platform
  • Partners
  • Find a Reseller
  • Partner Program
  • Partner Portal
  • About NXLog
  • Company
  • Careers
  • Support Portals
  • Contact Us

Follow us

LinkedIn Facebook YouTube Reddit
logo

© Copyright NXLog Ltd.

Subscribe to our newsletter

Privacy Policy • General Terms of Business