An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.
History

Wed, 30 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Jul 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic apm Server
Vendors & Products Elastic
Elastic apm Server

Wed, 30 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.
Title APM Server Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows Installer
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2025-07-30T00:12:43.639Z

Updated: 2025-07-30T14:06:16.977Z

Reserved: 2025-01-24T11:35:22.838Z

Link: CVE-2025-0712

cve-icon Vulnrichment

Updated: 2025-07-30T14:06:07.001Z

cve-icon NVD

Status : Received

Published: 2025-07-30T01:15:24.513

Modified: 2025-07-30T01:15:24.513

Link: CVE-2025-0712

cve-icon Redhat

No data.