An attacker requires local access and the ability to modify osqueryd configurations.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13061 | Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*:* |
Thu, 01 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 May 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations. | |
| Title | Elastic Agent Inclusion of Functionality from Untrusted Control Sphere | |
| Weaknesses | CWE-829 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2025-05-01T15:33:01.380Z
Reserved: 2024-11-18T14:48:22.150Z
Link: CVE-2024-52976
Updated: 2025-05-01T14:51:50.416Z
Status : Analyzed
Published: 2025-05-01T14:15:35.527
Modified: 2025-10-01T19:28:58.007
Link: CVE-2024-52976
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:06:01Z
EUVD