Elastic Defend for Windows Vulnerability Allows Threat Actors to Gain Elevated Access
Elastic has released a security advisory addressing a significant vulnerability in Elastic Defend that could allow attackers to escalate their privileges on Windows systems.The vulnerability, tracked as CVE-2025-37735, stems from improper preservation of…
Elastic has released a security advisory addressing a significant vulnerability in Elastic Defend that could allow attackers to escalate their privileges on Windows systems.The vulnerability, tracked as CVE-2025-37735, stems from improper preservation of file permissions in the Defend service and poses a serious risk to organizations relying on this endpoint protection platform.FieldDetailsCVE IDCVE-2025-37735Vulnerability TypeImproper Preservation of PermissionsAffected ProductElastic Defend for WindowsAffected Versions8.19.5 and earlier; 9.0.0 through 9.1.5Fixed Versions8.19.6, 9.1.6, 9.2.0CVSS v3.1 Score7.0 (High)Vulnerability OverviewThe flaw exists in how Elastic Defend handles file permissions on Windows hosts. When the Defend service, which runs with SYSTEM-level privileges, processes files on the system, it fails to preserve their original permission settings properly.This improper permission handling creates an attack vector that could allow local attackers to delete arbitrary files on the compromised system.In specific scenarios, this capability to delete critical system files could lead to local privilege escalation, enabling an attacker with limited user access to gain complete administrative control over the affected machine.This transforms what is a file-handling issue into a full-blown privilege escalation vulnerability that threatens the security posture of vulnerable organizations.The vulnerability affects multiple versions of Elastic Defend. Users running versions 8.19.5 and earlier are vulnerable, as are users operating versions 9.0.0 through 9.1.5.Organizations using these versions should treat this as a priority remediation item, as the vulnerability could be exploited by any local user on the system.The security rating reflects the serious nature of this issue. Elastic assigned the vulnerability a CVSS v3.1 score of 7.0 (High), with a vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A: H.The attack requires local access and moderate complexity. However, it demands only low privileges to execute, making it a realistic threat in many environments.Elastic has released patched versions addressing this vulnerability. Organizations should immediately upgrade to one of the following fixed versions: 8.19.6, 9.1.6, or 9.2.0.These updates implement proper permission preservation mechanisms, eliminating the attack vector.For organizations unable to upgrade immediately due to operational constraints or compatibility concerns, a temporary workaround is available.Windows 11 version 24H2 includes architectural changes that make this vulnerability significantly more complicated to exploit.Organizations running older Windows versions might consider upgrading to Windows 11 24H2 or later as an interim security measure while planning their Elastic Defend upgrade schedule.Security teams should prioritize patching this vulnerability across their infrastructure. The combination of local access requirements and user privileges means that employees or contractors with system access pose the primary risk.Additionally, compromised accounts with standard user access could leverage this flaw to gain administrative control.Organizations should inventory their Elastic Defend deployments, identify systems running vulnerable versions, and develop an upgrade timeline.Given the high severity rating and the realistic exploitation scenario, this should be treated as critical infrastructure maintenance rather than routine patching.CVE-2025-37735 represents a notable security concern for Windows environments running Elastic Defend.The vulnerability’s potential for privilege escalation demands prompt attention from affected organizations.Swift deployment of available patches will eliminate this threat and maintain the security integrity of the endpoint protection infrastructure.Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Based on reporting by GBHackers.
