First published: Tue Jan 24 2023(Updated: )
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Endgame | <=3.62.2 | |
Elastic Endpoint Security | <7.17.7 | |
Elastic Endpoint Security | >=8.0.0<8.4.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-38774.
CVE-2022-38774 has a severity rating of 7.8 (high).
Elastic Endpoint Security (versions up to 7.17.7 and between 8.0.0 and 8.4.0) and Elastic Endgame (version up to 3.62.2) for Windows are affected by CVE-2022-38774.
CVE-2022-38774 allows unprivileged users to elevate their privileges to those of the LocalSystem account.
No, Microsoft Windows systems are not vulnerable to CVE-2022-38774.