VendorsElasticendpoint_securityall versions
Vulnerabilities

Elastic Endpoint Security

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-38775
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Published 2023-01-24 · Modified
7.8EPSS 0.003
CVE-2022-38777
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Published 2023-02-08 · Modified
7.8EPSS 0.003
CVE-2022-38774
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Published 2023-01-24 · Modified
7.8EPSS 0.002
CVE-2022-23714
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Published 2022-07-06 · Modified
7.8EPSS 0.002
CVE-2023-46669
Elastic Agent / Elastic Endpoint Security local API key disclosure
Published 2025-05-01 · Analyzed
7.1EPSS 0.002
CVE-2026-56152
Incorrect Authorization in Elastic Defend Leading to Information Disclosure
Published 2026-07-01 · Modified
5.3EPSS 0.003