CVE-2025-29969 is a time-of-check time-of-use race condition in Microsoft Windows affecting the MS-EVEN EventLog RPC functionality exposed through the EventLog service. The flaw arises from inconsistent handling of a user-supplied event log file between an initial validation step and a later use step. Reported research indicates the vulnerable workflow involves opening a caller-controlled event log file path, validating the EVTX header, and later re-reading the file during a backup operation. By changing the contents of an attacker-controlled SMB-hosted file after the header check but before the subsequent read, an attacker can cause the service to process and write unintended content to a chosen destination on the target system. The issue has been described as enabling remote arbitrary file write and, in practical exploit chains, remote code execution in Active Directory domain networks. Public reporting specifically associates the vulnerable operations with MS-EVEN methods such as ElfrOpenBELW and ElfrBackupELFW.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small Python proof/weaponization set for CVE-2025-29969 (“EventLogin”), described as a TOCTOU issue in the Windows MS-EVEN (Event Log) protocol enabling low-privileged users to write arbitrary files to a remote machine. Structure: - README.md: Explains the vulnerability, prerequisites, and usage examples. Instructs hosting an SMB share via impacket-smbserver with a hardcoded share name 'Share'. - write_file_remotely.py: Weaponized exploit. Connects to the target’s EventLog service over DCERPC named pipe (ncacn_np to \\pipe\\eventlog), authenticates with provided low-privileged credentials, opens an EVTX file via a UNC path on an attacker-controlled SMB share (\\{smb_server_ip}\Share\...), then overwrites a temporary local copy of that EVTX with attacker-chosen file bytes and invokes hElfrBackupELFW to write to an arbitrary remote_file_path. This yields an arbitrary file write primitive on the target (commonly leveraged by writing to Startup folders or other execution points). - check_if_exists.py: Reconnaissance helper (not the full vulnerability). Uses the MS-EVEN hElfrOpenBELW call with a crafted RPC_UNICODE_STRING to probe a remote path and interprets specific NTSTATUS-like error codes to determine whether a file exists, exists as a directory, or does not exist. Useful for enumerating installed software or accessible directories using any domain user credentials. Notable implementation details: - Both scripts craft RPC_UNICODE_STRING with an extra null terminator (MaximumLength += 1), noting an Impacket/EventLog quirk. - Network interaction is entirely over SMB/DCERPC to the EventLog named pipe and (for the write primitive) an SMB file share reachable by the target. Overall purpose: provide an operational exploit to achieve arbitrary remote file write via MS-EVEN, plus a related primitive-based checker to remotely test file existence with low privileges.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution (RCE) vulnerability in Microsoft Windows’ MS-EVEN protocol used for reading live and backup event logs remotely.
A Microsoft Windows EventLog (MS-EVEN RPC) vulnerability that allows low-privileged remote users to achieve an arbitrary remote file write (via a TOCTOU condition around ElfrOpenBELW/ElfrBackupELFW handling of a remotely hosted EVTX), which can be leveraged for remote code execution in Active Directory domain environments (e.g., by writing to Startup folders or via DLL hijacking).
A vulnerability in MS-EVEN RPC described as remote code execution in the title (type field shows EoP in the source list).
A critical TOCTOU race condition vulnerability in Windows Fundamentals that can allow authorized attackers to achieve remote code execution against network-exposed Windows systems, particularly via crafted RPC or SMB requests.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.