PT-2025-18391 · Elastic · Agent

Published

2025-05-01

·

Updated

2025-05-02

·

CVE-2024-52976

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elastic Agent (affected versions not specified)
Description The issue allows local attackers to execute arbitrary code via parameter injection in the osqueryd subprocess of Elastic Agent. This can happen due to the inclusion of functionality from an untrusted control sphere. An attacker would need local access and the ability to modify osqueryd configurations to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-52976

Affected Products

Agent