We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-25011

Beats Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows Installer



Description

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.

Reserved 2025-01-31 | Published 2025-07-30 | Updated 2025-07-30 | Assigner elastic


HIGH: 7.0CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-427 Uncontrolled Search Path Element

Product status

Default status
unaffected

8.0.0 before 9.1.0
affected

References

discuss.elastic.co/...1-0-security-update-esa-2025-12/380558

cve.org (CVE-2025-25011)

nvd.nist.gov (CVE-2025-25011)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-25011

Support options

Helpdesk Chat, Email, Knowledgebase