CVE-2024-14047

A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated Winlogbeat operation to write to or delete arbitrary files. Successful exploitation could result in a denial of service.

  • Published Sep 1, 2026
  • CVSS 7.1 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2024-14047 at the National Vulnerability Database