An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 30 Jul 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Elastic
Elastic apm Server |
|
Vendors & Products |
Elastic
Elastic apm Server |
Wed, 30 Jul 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges. | |
Title | APM Server Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows Installer | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: elastic
Published: 2025-07-30T00:12:43.639Z
Updated: 2025-07-30T14:06:16.977Z
Reserved: 2025-01-24T11:35:22.838Z
Link: CVE-2025-0712

Updated: 2025-07-30T14:06:07.001Z

Status : Received
Published: 2025-07-30T01:15:24.513
Modified: 2025-07-30T01:15:24.513
Link: CVE-2025-0712

No data.