CVE-2024-14047
largeLocal link-resolution (symlink) flaw in Elastic Winlogbeat Windows installer
Winlogbeat's Windows installer placed runtime files in a directory writable by unprivileged users, creating an improper link-resolution issue (CWE-59). A low-privileged attacker who already has access to the host can pre-position malicious filesystem links so that a subsequent elevated Winlogbeat operation writes to or deletes arbitrary files. Successful exploitation results in denial of service, with high integrity and availability impact but no confidentiality impact per the CVSS 3.1 score of 7.1. Organizations running Winlogbeat on Windows hosts installed via the Windows installer are affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates the 30-day exploitation probability at about 0.1%.
What to do: Consult Elastic's security advisory for CVE-2024-14047 to identify the affected Windows installer versions and upgrade Winlogbeat to a fixed release. In the interim, check that the Winlogbeat installation directory and its runtime files are not writable by unprivileged users and restrict local access on hosts running it, watching for unexpected file deletions.
| Elastic Winlogbeat | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated Winlogbeat operation to write to or delete arbitrary files. Successful exploitation could result in a denial of service.
- Vendors
- elastic
- Products
- winlogbeat
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.