CyberRota Analysis
AI-GeneratedElastic Agent on Windows systems is vulnerable due to incorrect permission assignments, allowing local users to exploit overly broad access controls. This flaw can lead to local privilege escalation, enabling attackers to execute arbitrary code with SYSTEM-level privileges. Organizations using Elastic Agent in unprivileged mode should prioritize addressing this vulnerability to mitigate potential security risks.
Original NVD Description
Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.
Related CVEs
Other vulnerabilities affecting the same vendor(s)