ZeroHour

CVE-2024-14047

large

Local link-resolution (symlink) flaw in Elastic Winlogbeat Windows installer

CVSS 3.1
7.1 high
EPSS
<1%p1
Published
()
Modified
AI analysis

Winlogbeat's Windows installer placed runtime files in a directory writable by unprivileged users, creating an improper link-resolution issue (CWE-59). A low-privileged attacker who already has access to the host can pre-position malicious filesystem links so that a subsequent elevated Winlogbeat operation writes to or deletes arbitrary files. Successful exploitation results in denial of service, with high integrity and availability impact but no confidentiality impact per the CVSS 3.1 score of 7.1. Organizations running Winlogbeat on Windows hosts installed via the Windows installer are affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates the 30-day exploitation probability at about 0.1%.

What to do: Consult Elastic's security advisory for CVE-2024-14047 to identify the affected Windows installer versions and upgrade Winlogbeat to a fixed release. In the interim, check that the Winlogbeat installation directory and its runtime files are not writable by unprivileged users and restrict local access on hosts running it, watching for unexpected file deletions.

Affected
Elastic Winlogbeat
Estimated exposure
largeon the order of tens of thousands of Windows hosts (estimate; exact install counts unpublished) — Winlogbeat is a widely deployed Elastic Beats shipper used for Windows event log collection across the large Elastic Stack install base, but no public install counts or internet-exposure scans exist for it, so this is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated Winlogbeat operation to write to or delete arbitrary files. Successful exploitation could result in a denial of service.

Vendors
elastic
Products
winlogbeat
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.