Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NElastic Winlogbeat
APPElastic< 5.6.166.0.0 – 6.6.2 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same vendor
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2015-1427CRITICAL9.8⚠ KEVPL ✓same vendor
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
CVE-2025-37729CRITICAL9.1PL ✓same vendor
Elastic Cloud Enterprise — Server-Side Template Injection (SSTI) w silniku Jinjava
CVE-2025-25014CRITICAL9.1PL ✓same vendor
Prototype Pollution w Kibana prowadzące do RCE przez HTTP
CVE-2025-25015CRITICAL9.9PL ✓same vendor
Prototype Pollution w Elastic Kibana umożliwia zdalne wykonanie kodu (RCE)