Elastic Agent
cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*
- <= 7.17.24
- <= 8.15.3
A vulnerability in Elastic Agent versions through 7.17.24 and 8.15.3 allows local attackers to execute arbitrary code by injecting parameters into the osqueryd subprocess. This issue arises from the inclusion of functionality from an untrusted control sphere, which local attackers can exploit if they have access to modify osqueryd configurations.
Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code within the context of the Elastic Agent.
Users can upgrade to Elastic Agent versions 7.17.25 or 8.15.4 and above to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.