CVE-2022-23714

HIGH EXPLOITED RANSOMWARE

Elastic Endpoint Security 7.13.0-7.17.3 - Local Privilege Escalation via Ransomware Canaries Feature

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-23714 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns.

Description

A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.elastic.co/community/security

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 10.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-01-17
Ransomware Use Confirmed
CWE
CWE-264
Status published
Products (1)
elastic/endpoint_security 7.13.0 - 7.17.4
Published Jul 06, 2022
Tracked Since Feb 18, 2026