CVE-2022-23714

EUVD-2022-28650
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
Affected Products (NVD)
VendorProductVersion
elasticendpoint_security
7.13.0 ≤
𝑥
≤ 7.17.4
elasticendpoint_security
8.0.0 ≤
𝑥
≤ 8.2.3
𝑥
= Vulnerable software versions
Common Weakness Enumeration