First published: Wed Jul 06 2022(Updated: )
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Endpoint Security | >=7.13.0<=7.17.4 | |
Elastic Endpoint Security | >=8.0.0<=8.2.3 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-23714.
CVE-2022-23714 has a severity value of 7.8, which is considered high.
The affected software is Elastic Endpoint Security for Windows versions 7.13.0 to 7.17.4, and versions 8.0.0 to 8.2.3.
Unprivileged users can exploit CVE-2022-23714 to elevate their privileges to those of the LocalSystem account.
Yes, you can find more information about CVE-2022-23714 at the following references: - [Elastic Discuss](https://discuss.elastic.co/t/elastic-8-3-1-8-3-0-and-7-17-5-security-update/308613) - [Elastic Security](https://www.elastic.co/community/security)