Executive brief
Winlogbeat is a Windows monitoring tool that collects event log data. A flaw in its Windows installer places runtime files in a directory that unprivileged users can write to. An attacker with local access could use symbolic links to trick an elevated Winlogbeat process into writing or deleting arbitrary files, disrupting system operations or enabling further compromise.
Technical details
This is an improper link resolution vulnerability (CWE-59, symlink attack) in the Winlogbeat Windows MSI installer. Runtime files are placed in a world-writable directory, allowing a low-privileged attacker to pre-position malicious symbolic links. When Winlogbeat runs with elevated privileges, it follows these links and performs file operations (write or delete) on attacker-chosen targets. Attack requires local system access and user interaction to trigger an elevated Winlogbeat operation. The vulnerability affects all versions 7.6.0 through 8.12.2 on Windows; macOS and Linux are not affected. It is patched in version 8.13.0 and later.
Affected products
- Elastic Winlogbeat 7.6.0 through 8.12.2
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Fixed in version 8.13.0