CVE-2022-38774
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Affected (3)
Products: Elastic: Endgame, Endpoint Security
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.62.2 | |
| Before 7.17.7 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (4)
Source: security@elastic.co
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.