Local Privilege Escalation in Suricata's Windows Service Installation Process
CVE-2026-57223
7HIGH
What is CVE-2026-57223?
A security flaw in Suricata, a prominent network intrusion detection and prevention system, allows for local privilege escalation via its Windows service installation process. If the application is installed in a directory path that includes spaces and one of the earlier path components is writable by a user with low privileges, an attacker could exploit this to execute arbitrary code with LocalSystem privileges. This vulnerability is addressed in Suricata versions 7.0.17 and 8.0.6.
Affected Version(s)
suricata >= 8.0.0, < 8.0.6 < 8.0.0, 8.0.6
suricata < 7.0.17 < 7.0.17
