← Back

CVE-2024-52976

nvd nist
Published: May 1, 2025Modified: Oct 1, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations.

Affected (2)

1 product
Elastic Agent
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Elastic
Before 7.17.25
From 8.0.0 to 8.15.4

Timeline

No history available yet.