Описание
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Ссылки
- MitigationVendor Advisory
- Vendor Advisory
- MitigationVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.13.0 (включая) до 7.17.4 (включая)Версия от 8.0.0 (включая) до 8.2.3 (включая)
Одновременно
Одно из
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 30%
0.0011
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-264
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
EPSS
Процентиль: 30%
0.0011
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-264
NVD-CWE-noinfo