Impact
The flaw in Winlogbeat’s installation process allows a local attacker to exploit improper link resolution before file access, identified as CWE‑59. When a user runs the installer, runtime files are placed in a directory that non‑privileged users can write to. An attacker who can create malicious filesystem links in that directory can then cause a later elevated Winlogbeat operation to write to or delete arbitrary files, effectively breaking the service and potentially leading to a denial of service.
Affected Systems
Elastic’s Winlogbeat component, part of Elastic Security. No specific version range is given in the advisory, but the mention of a security update for Winlogbeat 8.13.0 indicates that versions prior to that are affected.
Risk and Exploitability
The CVSS score of 7.2 assigns this as high impact. EPSS data is not available, so formal exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local: a low‑privileged attacker with system access needs only to create the malicious link; no network privileges are required. Successful exploitation can overwrite or delete crucial files used by Winlogbeat, causing a loss of functionality. Given the lack of external exposure, the primary risk is to systems that have already installed the vulnerable version.
OpenCVE Enrichment