Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an unquoted service ImagePath to CreateServiceA. When Suricata is installed below a path containing spaces and an earlier path component is writable by a local low-privileged attacker, Windows can execute an attacker-controlled program as LocalSystem, resulting in local privilege escalation. This issue is fixed in versions 8.0.6 and 7.0.17.
Published: 2026-09-18
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation via Windows service ImagePath exploitation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when the Suricata Windows service installer provides an unquoted ImagePath to the Windows CreateServiceA API. This oversight allows an attacker who can write to a writable component of the installation path to execute an attacker‑controlled executable as the LocalSystem account. The result is a full local privilege escalation, granting the attacker administrator‑level access to the machine. The weakness is classified as CWE‑428, improper handling of a privileged service configuration.

Affected Systems

The issue affects OISF Suricata releases prior to version 7.0.17 and 8.0.6 on Windows platforms. Any deployment that installs Suricata under a directory path that contains spaces, where an earlier component of that path is writable by a low‑privileged local user, is vulnerable. Versions 7.0.17 and 8.0.6 contain the fix.

Risk and Exploitability

The CVSS base score of 7 indicates a high impact if exploitation succeeds. EPSS information is not available, so the exploitation probability cannot be quantified, but the flaw can be triggered by any local user able to write to the relevant path component, which is a common scenario on shared or poorly locked down systems. The vulnerability is not listed in the CISA KEV catalog, but the critical nature of the fix suggests immediate attention. Attackers can exploit the flaw via the standard Windows service creation process, creating a scenario where a local attacker can elevate privileges without additional expertise.

Generated by OpenCVE AI on September 19, 2026 at 10:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Suricata release 7.0.17 or newer 8.0.6 that contains the image path quoting fix
  • If upgrading is not feasible, reinstall Suricata into a path that contains no spaces and ensure the installation directory is not writable by non‑privileged users
  • Verify that the service ImagePath is properly quoted during installation and does not expose writable path components

Generated by OpenCVE AI on September 19, 2026 at 10:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an unquoted service ImagePath to CreateServiceA. When Suricata is installed below a path containing spaces and an earlier path component is writable by a local low-privileged attacker, Windows can execute an attacker-controlled program as LocalSystem, resulting in local privilege escalation. This issue is fixed in versions 8.0.6 and 7.0.17.
Title Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalation
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T15:50:19.808Z

Reserved: 2026-06-24T02:21:33.811Z

Link: CVE-2026-57223

cve-icon Vulnrichment

Updated: 2026-09-22T15:50:11.743Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:17:00.787

Modified: 2026-09-29T12:48:12.460

Link: CVE-2026-57223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:45:08Z

Weaknesses
  • CWE-428

    Unquoted Search Path or Element