CVE-2025-37735: High severity Elastic Defend vulnerability
Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37735?
CVE-2025-37735 is considered a high-severity vulnerability due to its potential for local privilege escalation.
How does CVE-2025-37735 affect Elastic Defend?
CVE-2025-37735 allows the Defend service running as SYSTEM to improperly delete arbitrary files on Windows hosts.
How do I fix CVE-2025-37735?
To mitigate CVE-2025-37735, users should apply the latest security updates provided by Elastic for Elastic Defend.
What systems are affected by CVE-2025-37735?
CVE-2025-37735 affects Elastic Defend running on Windows hosts.
What could be the consequences of exploiting CVE-2025-37735?
Exploiting CVE-2025-37735 could lead to unauthorized file deletions and potential escalation of privileges on the affected system.