ZeroHour

CVE-2024-52976

CVSS 3.1
7.8 high
EPSS
<1%p10
Published
()
Modified
Description

Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations.

Vendors
elastic
Products
elastic agent
Weakness
CWE-829
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.