Local Vulnerability in Winlogbeat Installer Affects Windows Systems
CVE-2024-14047

7.2HIGH

Key Information:

Vendor

Elastic

Vendor
CVE Published:
1 September 2026

What is CVE-2024-14047?

A local vulnerability exists in the Winlogbeat Windows installer that allows runtime files to be stored in directories accessible to unprivileged users. This flaw enables an attacker with existing local access to pre-position malicious filesystem links. If a subsequent elevated operation of Winlogbeat occurs, it can inadvertently write to or delete arbitrary files, thus posing a significant risk of denial of service. It is critical for users to apply the necessary security updates to mitigate this risk.

Affected Version(s)

Elastic Security 7.6.0 <= 8.12.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.