First published: Wed Feb 08 2023(Updated: )
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic | <3.62.3 | |
Elastic Endpoint | <7.17.9 | |
Elastic Endpoint | >=8.0.0<8.5.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38777 is an issue discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Elastic Endgame versions up to 3.62.3, Elastic Endpoint Security versions up to 7.17.9, and Elastic Endpoint Security versions between 8.0.0 and 8.5.0 are affected.
CVE-2022-38777 has a severity rating of 7.8, which is considered high.
CVE-2022-38777 can be exploited by unprivileged users to elevate their privileges to those of the LocalSystem account.
Yes, security updates are available. Please refer to the reference URLs provided for more information.