CVE-2022-23714
Summary
| CVE | CVE-2022-23714 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-06 14:15:00 UTC |
| Updated | 2023-07-03 20:34:00 UTC |
| Description | A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elastic | Endpoint Security | All | All | All | All |
| Application | Elastic | Endpoint Security | All | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Elastic 8.3.1, 8.3.0, and 7.17.5 Security Update - Security Announcements - Discuss the Elastic Stack | MISC | discuss.elastic.co | |
| www.elastic.co/community/security | MISC | www.elastic.co | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.