PT-2025-45184 · Elastic · Defend

Published

2025-11-06

·

Updated

2025-12-15

·

CVE-2025-37735

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elastic Defend (affected versions not specified)
Description An issue exists in Elastic Defend on Windows hosts where improper preservation of permissions can allow the Defend service, running as SYSTEM, to delete arbitrary files on the system. This could potentially lead to local privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

BDU:2025-16418
CVE-2025-37735

Affected Products

Defend