Elastic Agent osqueryd Subprocess Code Execution Vulnerability

Vulnerability

A vulnerability in Elastic Agent versions through 7.17.24 and 8.15.3 allows local attackers to execute arbitrary code by injecting parameters into the osqueryd subprocess. This issue arises from the inclusion of functionality from an untrusted control sphere, which local attackers can exploit if they have access to modify osqueryd configurations.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code within the context of the Elastic Agent.

Remediation

Users can upgrade to Elastic Agent versions 7.17.25 or 8.15.4 and above to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.2
impact
10.0
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.