ZeroHour

CVE-2026-78604

large

Insecure File Permissions Enable Local Privilege Escalation in Elastic Agent on Windows

CVSS 3.1
7.8 high
EPSS
<1%p1
Published
()
Modified
AI analysis

Elastic Agent on Windows, when installed in unprivileged mode, creates resources used by the agent service with access-control permissions broader than required (CWE-732, incorrect permission assignment for critical resource). A local attacker with low privileges can exploit this by replacing the agent service's binaries (CAPEC-642), causing the service to execute attacker-chosen code. Because the agent service runs in a privileged context, this results in full SYSTEM-level privileges on the affected Windows host. Only Windows systems where Elastic Agent was installed in unprivileged mode are affected, per the vendor description. There is currently no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only about a 0.1% probability of exploitation in the next 30 days.

What to do: Inventory Windows endpoints running Elastic Agent and identify which were installed in unprivileged mode, as those are the affected hosts. Upgrade those agents to the patched release cited in Elastic's security advisory (Elastic is the CNA; check elastic.co/security for the exact fixed version). As an interim mitigation, verify and restrict ACLs on the Elastic Agent installation directory and service resources so unprivileged users cannot write to or replace the service binaries.

Affected
Elastic Agent
Estimated exposure
largeon the order of tens of thousands to low hundreds of thousands of Windows endpoints (unprivileged-mode Elastic Agent installs) — Elastic does not publish agent install counts; the estimate assumes the subset of Elastic Agent fleets at Elastic's tens of thousands of customer organizations that run on Windows in unprivileged mode, since the default Windows install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.

Vendors
elastic
Products
elastic agent
Weakness
CWE-732
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.