CNNVD-202511-685 Information

CNNVD ID

CNNVD-202511-685

CVE-2025-37735

  • CNNVD Published: 2025-11-06

Description (Chinese)

Elastic Defend是荷兰Elastic公司的一款应用程序。提供预防、检测和响应功能,以及对 EPP、EDR、SIEM 和安全分析的深度可见性。 Elastic Defend存在安全漏洞,该漏洞源于Windows主机上权限保存不当,可能导致Defend服务删除系统上的任意文件,在某些情况下可能导致本地权限提升。

Description (English)

Elastic Defend is an application of the Dutch company Elastic. Provide prevention, detection and response functions, as well as depth visibility for EPP, EDR, SIEM and security analysis. Elastic Defend has a security loophole, which stems from the improper preservation of privileges on the Windows mainframe, which may lead to the deletion of random files from the Devend service system and, in some cases, to the enhancement of local rights.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Elastic

Published

2025-11-06

Last Modified

2026-02-24

References

https://discuss.elastic.co/t/elastic-defend-8-19-6-9-1-6-and-9-2-0-security-update-esa-2025-23/383272

Patch

https://discuss.elastic.co/t/elastic-defend-8-19-6-9-1-6-and-9-2-0-security-update-esa-2025-23/383272

Share on: