CVE-2024-52976

MEDIUM

Elastic Agent subprocess - Code Injection

Title source: llm
STIX 2.1

Description

Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations.

Scores

CVSS v3 4.4
EPSS 0.0006
EPSS Percentile 18.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-829
Status published
Products (1)
elastic/elastic_agent < 7.17.25
Published May 01, 2025
Tracked Since Feb 18, 2026