Unrated severityNVD Advisory· Published May 1, 2025· Updated May 1, 2025
Elastic Agent Inclusion of Functionality from Untrusted Control Sphere
CVE-2024-52976
Description
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection.
An attacker requires local access and the ability to modify osqueryd configurations.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: 7.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.