CVE-2025-25011

7.0

Elastic · Beats

Elastic Beats is vulnerable to an uncontrolled search path element flaw allowing local privilege escalation via insecure directory permissions.

Executive summary

A high-severity local privilege escalation vulnerability in Elastic Beats allows local attackers to potentially gain SYSTEM-level access through insecure directory permissions.

Vulnerability

This vulnerability, classified as an uncontrolled search path element (CWE-427), stems from improper handling of directory permissions. An authenticated local user can exploit this weakness to manipulate arbitrary files and escalate their privileges to SYSTEM.

Business impact

Successful exploitation of this vulnerability permits a local user to compromise the integrity and availability of the host system. Given the CVSS score of 7.0, this represents a significant risk to systems where untrusted local users have access, as it facilitates full administrative control over the affected machine.

Remediation

Immediate Action: Update all instances of Elastic Beats to version 9.1.0 or later to resolve the underlying directory permission flaw.

Proactive Monitoring: Review system logs for unauthorized file modifications or suspicious process execution patterns originating from standard user accounts.

Compensating Controls: Implement strict file system access controls and monitoring on the installation directories of Elastic Beats to restrict unauthorized modifications by non-administrative users.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a clear path for local privilege escalation, which is a significant security concern for any enterprise environment. Administrators must prioritize updating Elastic Beats to version 9.1.0 to ensure that directory permissions are properly secured, thereby preventing unauthorized escalation to SYSTEM privileges.

More Elastic CVEs

Sources