CVE-2022-38774
Published on: Not Yet Published
Last Modified on: 02/03/2023 06:21:00 PM UTC
Certain versions of Endgame from Elastic contain the following vulnerability:
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
- CVE-2022-38774 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Elastic - Elastic Endpoint Security and Elastic Endgame Security version Elastic Security versions up to 7.17.6 and 8.3.3 and Elastic Endgame versions up to 3.62.2
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Endpoint Security 8.4.0/7.17.7 and Endgame 3.62.3 Security Statement - Security Announcements - Discuss the Elastic Stack | discuss.elastic.co text/html |
![]() |
Security issues | Elastic | www.elastic.co text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Elastic | Endgame | All | All | All | All |
Application | Elastic | Endpoint Security | All | All | All | All |
Operating System | Microsoft | Windows | - | All | All | All |
- cpe:2.3:a:elastic:endgame:*:*:*:*:*:*:*:*:
- cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
『allow unprivileged users to elevate their privileges to those of the LocalSystem account.』 CVE-2022-38774 Endpoin… twitter.com/i/web/status/1… | 2023-01-24 15:25:56 |
![]() |
Potentially Critical CVE Detected! CVE-2022-38774 An issue was discovered in the quarantine feature of Elastic Endp… twitter.com/i/web/status/1… | 2023-01-24 16:55:56 |
![]() |
CVE-2022-38774 : An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame… twitter.com/i/web/status/1… | 2023-01-26 21:40:43 |