AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-37735

HIGH · CVSS 7 EPSS 0.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-11-06 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.0. It affects Windows.

CVE
CVE-2025-37735
Severity
HIGH
CVSS
7
EPSS
0.13%
Windows

Original NVD Description

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.