Executive brief
Elastic Agent, a monitoring and endpoint protection tool used to collect security data from systems, is vulnerable to local privilege escalation on Windows when installed in unprivileged mode. An attacker with basic user access can exploit overly permissive file permissions to inject malicious code and gain SYSTEM-level control of the host, potentially compromising the entire system and any data it holds.
Technical details
This vulnerability stems from incorrect permission assignment (CWE-732) in Elastic Agent's critical resources on Windows systems deployed in unprivileged installation mode. The agent service creates files and directories with access controls broader than required, allowing local users to replace binaries (CAPEC-642). An attacker with local user privileges (low barrier to entry, no authentication required beyond system login) can overwrite executable files used by the service to execute arbitrary code with SYSTEM privileges. The vulnerability is Windows-specific and only affects unprivileged installations; default privileged installations and all Linux/macOS deployments are unaffected. Fixes are available in Elastic Agent versions 8.19.21, 9.4.6, and 9.5.2.
Affected products
- Elastic Agent 8.0.0–8.19.20, 9.0.0–9.4.5, 9.5.0–9.5.1
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fixed in versions 8.19.21, 9.4.6, 9.5.2