Medium severity4.4NVD Advisory· Published May 1, 2025· Updated Jun 17, 2026
CVE-2024-52976
CVE-2024-52976
Description
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection.
An attacker requires local access and the ability to modify osqueryd configurations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- discuss.elastic.co/t/elastic-agent-7-17-25-and-8-15-4-security-update-esa-2024-39/377708nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.