Impact
An unhandled exception occurs in Elastic Endpoint’s file‑path handling routine when a specially crafted file name is processed under certain system locale settings, such as Chinese, Japanese, and Korean locales on Windows. The exception is not caught and causes the Elastic Endpoint process to crash and restart repeatedly. This brings down the real‑time malware prevention and behavioral detection functions on the host, which can be sustained for as long as the offending condition persists, effectively disrupting security controls.
Affected Systems
The flaw affects Elastic’s Elastic Agent and Elastic Defend products. It is observed on Windows environments where the system locale is set to Chinese, Japanese, or Korean. Exact version details are not supplied in the advisory, but the issue was identified in the context of recent releases of Elastic Endpoint.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.2, indicating moderate severity. Because EPSS data is unavailable, the current exploitation likelihood cannot be quantified, and the issue is not listed in CISA KEV. An attacker can trigger the denial of service by delivering a file name that triggers the exception, typically by placing a malicious artifact on the host or instructing the local endpoint to process a crafted filename. The impact is isolated to the local host that runs the Elastic Endpoint component, but in a network where multiple host agents rely on Elastic Defend, the outage could propagate indirect availability problems.
OpenCVE Enrichment