Skip to content
ElasticCVE-2024-14047

Elastic Security: denial of service

High7.2CVE-2024-14047 · Published Sep 1, 2026 · updated Sep 10, 2026

A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated Winlogbeat operation to write to or delete arbitrary files. Successful exploitation could result in a denial of service.

Elastic advisory

Affected versions

PackageAffectedFixed in
Elastic Security
Product
>= 7.6.0, <= 8.12.2No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-59

More Elastic advisories

All Elastic
Advisory
Elasticsearch: missing authorization
Medium5.4Sep 1
Elastic Kibana: missing authorization
Medium6.5Sep 1
Elastic Kibana: path traversal
High7.3Sep 1
Elastic Kibana: missing authorization
Medium4.3Sep 1
Elastic Kibana: missing authorization
Medium4.3Sep 1
Elasticsearch: request smuggling
Medium5.9Sep 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.