Impact
The vulnerability arises when the Suricata Windows service installer provides an unquoted ImagePath to the Windows CreateServiceA API. This oversight allows an attacker who can write to a writable component of the installation path to execute an attacker‑controlled executable as the LocalSystem account. The result is a full local privilege escalation, granting the attacker administrator‑level access to the machine. The weakness is classified as CWE‑428, improper handling of a privileged service configuration.
Affected Systems
The issue affects OISF Suricata releases prior to version 7.0.17 and 8.0.6 on Windows platforms. Any deployment that installs Suricata under a directory path that contains spaces, where an earlier component of that path is writable by a low‑privileged local user, is vulnerable. Versions 7.0.17 and 8.0.6 contain the fix.
Risk and Exploitability
The CVSS base score of 7 indicates a high impact if exploitation succeeds. EPSS information is not available, so the exploitation probability cannot be quantified, but the flaw can be triggered by any local user able to write to the relevant path component, which is a common scenario on shared or poorly locked down systems. The vulnerability is not listed in the CISA KEV catalog, but the critical nature of the fix suggests immediate attention. Attackers can exploit the flaw via the standard Windows service creation process, creating a scenario where a local attacker can elevate privileges without additional expertise.
OpenCVE Enrichment