Impact
Elastic Agent incorrectly assigns permissions to critical resources, exposing a local privilege escalation path that can elevate a user to SYSTEM. The flaw stems from overly permissive access controls applied to binaries and service resources when the agent runs in unprivileged mode on Windows. An attacker who owns an account on the host can replace or modify the agent’s executable binaries, leading the service to run malicious code and gaining full system privileges.
Affected Systems
The vulnerability affects Elastic Agent installations on Windows platforms that are configured to operate in unprivileged mode. The flaw exists regardless of the specific agent version, since the issue lies in the default permission configuration during resource creation. No specific product version range is listed.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and although a precise EPSS value is not available, the potential for exploitation remains significant due to the local user’s ability to manipulate files normally protected by service permissions. The exploit utilizes the Replace Binaries weakness (CAPEC-642), requiring only local access; no network exposure is needed. The vulnerability is not yet listed in CISA’s KEV catalog, but its impact on Windows systems warrants immediate remediation.
OpenCVE Enrichment