CVE-2022-23714: High severity elastic endpoint vulnerability
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-23714.
What is the severity of CVE-2022-23714?
CVE-2022-23714 has a severity value of 7.8, which is considered high.
What is the affected software?
The affected software is Elastic Endpoint Security for Windows versions 7.13.0 to 7.17.4, and versions 8.0.0 to 8.2.3.
How can unprivileged users exploit CVE-2022-23714?
Unprivileged users can exploit CVE-2022-23714 to elevate their privileges to those of the LocalSystem account.
Are there any references for CVE-2022-23714?
Yes, you can find more information about CVE-2022-23714 at the following references: - [Elastic Discuss](https://discuss.elastic.co/t/elastic-8-3-1-8-3-0-and-7-17-5-security-update/308613) - [Elastic Security](https://www.elastic.co/community/security)