CVE-2022-38777
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Affected (3)
Products: Elastic: Endgame, Endpoint Security
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.62.3 | |
| Before 7.17.9 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (4)
Source: security@elastic.co
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.