CVE-2022-38775

An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

03 Feb 2023, 18:24

Type Values Removed Values Added
References (MISC) https://www.elastic.co/community/security - (MISC) https://www.elastic.co/community/security - Vendor Advisory
References (MISC) https://discuss.elastic.co/t/endpoint-security-8-4-1-security-statement/323753 - (MISC) https://discuss.elastic.co/t/endpoint-security-8-4-1-security-statement/323753 - Vendor Advisory
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE NVD-CWE-noinfo
First Time Elastic endpoint Security
Microsoft windows
Microsoft
Elastic

26 Jan 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-26 21:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-38775

Mitre link : CVE-2022-38775

CVE.ORG link : CVE-2022-38775


JSON object : View

Products Affected

microsoft

  • windows

elastic

  • endpoint_security
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management