CVE-2024-52976: Elastic Agent Inclusion of Functionality from Untrusted Control Sphere
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection.
An attacker requires local access and the ability to modify osqueryd configurations.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52976?
CVE-2024-52976 is rated as a high severity vulnerability due to its potential to allow local attackers to execute arbitrary code.
How do I fix CVE-2024-52976?
To fix CVE-2024-52976, users should update to the latest version of Elastic Agent that addresses this vulnerability.
What is the impact of CVE-2024-52976?
The impact of CVE-2024-52976 includes the ability for local attackers to execute arbitrary code by injecting parameters into osqueryd configurations.
Who is affected by CVE-2024-52976?
CVE-2024-52976 affects users of Elastic Agent, particularly those who allow local access and have the ability to modify osqueryd configurations.
Can remote attackers exploit CVE-2024-52976?
No, CVE-2024-52976 requires local access, meaning only users with local permissions can exploit this vulnerability.