7.8
CVE-2024-52976
- EPSS 0.06%
- Veröffentlicht 01.05.2025 13:03:58
- Zuletzt bearbeitet 01.10.2025 19:28:58
- Quelle bressers@elastic.co
- CVE-Watchlists
- Unerledigt
Elastic Agent Inclusion of Functionality from Untrusted Control Sphere
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elastic ≫ Elastic Agent Version < 7.17.25
Elastic ≫ Elastic Agent Version >= 8.0.0 < 8.15.4
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.188 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| bressers@elastic.co | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.