Cyber Security News

Elastic Defend for Windows Vulnerability Let Attackers Escalate Privileges

Elastic has disclosed a significant security vulnerability in Elastic Defend for Windows that could allow attackers to escalate their privileges on affected systems.

Tracked as CVE-2025-37735 and designated as ESA-2025-23, the flaw stems from improper permission preservation within the Defend service running with SYSTEM-level privileges.

The vulnerability exists in how Elastic Defend handles file permissions on Windows hosts.

Elastic Defend for Windows Vulnerability

Because the Defend service runs with SYSTEM privileges, the highest permission level in Windows, an attacker with local access could exploit this flaw to delete arbitrary files on the system.

In specific scenarios, this capability could be weaponized to achieve local privilege escalation, granting unauthorized users administrative access to the compromised machine.

This type of vulnerability is hazardous because it bridges the gap between lower-privilege user accounts and complete system control.

The vulnerability impacts Elastic Defend across multiple versions. Versions up to and including 8.19.5. Versions 9.0.0 through 9.1.5.

Making an attractive target for threat actors seeking to deepen their foothold on compromised networks. The vulnerability carries a CVSS v3.1 score of 7.0, classified as High severity.

AttributesDetails
CVE IDCVE-2025-37735
Vulnerability TypeImproper Preservation of Permissions
Affected ProductElastic Defend for Windows
Affected Versions8.19.5 and earlier; 9.0.0 through 9.1.5
Fixed Versions8.19.6, 9.1.6, 9.2.0
CVSS v3.1 Score7.0 (High)

The attack vector requires local access and higher privileges than a typical user account, but notably does not require user interaction.

Organizations running these versions should treat this disclosure as urgent and prioritize remediation immediately.

Elastic recommends users upgrade to patched versions as the primary mitigation strategy.

The fixed versions are 8.19.6, 9.1.6, or 9.2.0. These updates directly address the permission preservation issue and eliminate the exploitation pathway.

For organizations unable to upgrade immediately, Windows11 24H2 includes architectural changes that make exploitation significantly more difficult.

Administrators without the ability to patch Elastic Defend quickly should consider upgrading to Windows 11 24H2 or later as an interim protective measure.

Organizations should prioritize upgrading Elastic Defend installations to eliminate this vulnerability.

Those operating older Windows versions without immediate upgrade paths should implement this as a secondary mitigation while planning their upgrade schedule.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago