CVE Vulnerabilities

CVE-2022-23714

Published: Jul 06, 2022 | Modified: Jul 03, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.

Affected Software

Name Vendor Start Version End Version
Endpoint_security Elastic 7.13.0 (including) 7.17.4 (including)
Endpoint_security Elastic 8.0.0 (including) 8.2.3 (including)

References