Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection.
An attacker requires local access and the ability to modify osqueryd configurations.
Metrics
Affected Vendors & Products
References
History
Thu, 01 May 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations. | |
Title | Elastic Agent Inclusion of Functionality from Untrusted Control Sphere | |
Weaknesses | CWE-829 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: elastic
Published: 2025-05-01T13:03:58.672Z
Updated: 2025-05-01T15:33:01.380Z
Reserved: 2024-11-18T14:48:22.150Z
Link: CVE-2024-52976

No data.

Status : Received
Published: 2025-05-01T14:15:35.527
Modified: 2025-05-01T14:15:35.527
Link: CVE-2024-52976

No data.