An attacker requires local access and the ability to modify osqueryd configurations.
Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Oct 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*:* |
Thu, 01 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 01 May 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations. | |
Title | Elastic Agent Inclusion of Functionality from Untrusted Control Sphere | |
Weaknesses | CWE-829 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2025-05-01T15:33:01.380Z
Reserved: 2024-11-18T14:48:22.150Z
Link: CVE-2024-52976

Updated: 2025-05-01T14:51:50.416Z

Status : Analyzed
Published: 2025-05-01T14:15:35.527
Modified: 2025-10-01T19:28:58.007
Link: CVE-2024-52976

No data.

Updated: 2025-07-12T23:06:01Z