CVE-2024-52976 - CERT CVE
ID CVE-2024-52976
Sažetak Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations.
Reference
CVSS
Base: 4.4
Impact: 3.6
Exploitability:0.8
Pristup
VektorSloženostAutentikacija
LOCAL LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
NONE HIGH NONE
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Zadnje važnije ažuriranje 02-05-2025 - 13:53
Objavljeno 01-05-2025 - 14:15