An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.
History

Wed, 30 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Jul 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elastic Beats
Vendors & Products Elastic
Elastic elastic Beats

Wed, 30 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.
Title Beats Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows Installer
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2025-07-30T00:15:43.132Z

Updated: 2025-07-30T14:03:41.113Z

Reserved: 2025-01-31T15:28:16.917Z

Link: CVE-2025-25011

cve-icon Vulnrichment

Updated: 2025-07-30T14:03:36.814Z

cve-icon NVD

Status : Received

Published: 2025-07-30T01:15:24.707

Modified: 2025-07-30T01:15:24.707

Link: CVE-2025-25011

cve-icon Redhat

No data.