---
id: CVE-2024-14047
title: >-
  A local vulnerability in the Winlogbeat Windows installer caused runtime files
  to be placed in a directory writable by unprivileged users
summary: >-
  A local vulnerability in the Winlogbeat Windows installer caused runtime files
  to be placed in a directory writable by unprivileged users. A low-privileged
  attacker with existing access to the system could pre-position malicious
  filesyst…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H'
cwe:
  - CWE-59
vendor: elastic
product: winlogbeat
affected:
  - 'winlogbeat >= 7.6.0, < 8.13.0'
patched:
  - winlogbeat 8.13.0
published: '2026-09-01'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T19:21:31.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-14047'
references:
  - url: >-
      https://discuss.elastic.co/t/winlogbeat-8-13-0-security-update-esa-2024-49/390044
    label: security@elastic.co
tags:
  - nvd
epss: 0.00107
epssPercentile: 0.01054
ingestedAt: '2026-09-10T20:04:29.976Z'
---

## Overview

A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated Winlogbeat operation to write to or delete arbitrary files. Successful exploitation could result in a denial of service.

## Affected

- `winlogbeat >= 7.6.0, < 8.13.0`

## Remediation

Upgrade past the affected range:

- `winlogbeat 8.13.0`
