Elastic Beats
cpe:2.3:a:elastic:elastic_beats:*:*:*:*:*:*:*
- < 9.1.0
A vulnerability in Elastic Beats Windows Installer versions prior to 9.1.0 allows for local privilege escalation. This uncontrolled search path element issue arises from improper handling of directory permissions, creating insecure directory permissions. An attacker with local access could exploit this vulnerability to move and delete arbitrary files, potentially gaining SYSTEM privileges.
Exploitation of this vulnerability could result in unauthorized access to SYSTEM privileges, allowing an attacker to manipulate files and potentially disrupt system operations.
Users can upgrade to Elastic Beats version 9.1.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.