Skip to main content

CVE-2025-24084 - WSL Uninstall

Summary​

Detects and removes Windows Subsystem for Linux (WSL) and related components only when WSL is present.

Dependencies​

Target​

This monitor should target the group shown below:

Image

Monitor Creation​

Step 1​

Navigate to ENDPOINTS ➞ Alerts ➞ Monitors

Step1

Step 2​

Locate the Create Monitor button on the right-hand side of the screen and click on it.
Step2

This page will appear after clicking on the Create Monitor button:
Step3

Step 3​

Fill in the mandatory columns on the left side

  • Name: CVE-2025-24084 - WSL Uninstall
  • Description: Detects and removes Windows Subsystem for Linux (WSL) and related components only when WSL is present.
  • Type: Script
  • Severity: Critical Impact Alerts
  • Family: Windows Services

Image

Step 4​

Click the Select Target button to choose the endpoints for running the monitor set.
Step4

This page will appear after clicking on the Select Target button:
Step5

Click on Device Groups and select Machines Opted for WSL Uninstallation Image

Conditions​

  • Run script on: Schedule

  • Repeat every: 24 Hours

  • Script Language: PowerShell

  • Use Generative AI Assist for script creation: False

  • PowerShell Script Editor:

    Navigate to the cw-rmm repository, open the script linked below, copy the raw code, and paste it into the RMM script editor:

    PowerShell Script

  • Criteria: Contains

  • Operator: AND

  • Script Output: Cleanup completed with

  • Escalate ticket on script failure: Disabled

  • Add Automation: ``

Image

Ticket Resolution​

  • Automatically Resolve: Enabled
  • Dropdown Option: Run same script as above
  • Criteria: Contains
  • Operator: AND
  • Script Output: No WSL component or residue detected.

Image

Monitor Output​

  • Output: Generate Ticket

Image

Completed Monitor​

Image

Changelog​

2026-09-16​

  • Initial version of the document