HomeSecurityElastic EDR: Zero-day allows malware execution & BSOD

Elastic EDR: Zero-day allows malware execution & BSOD

A new zero-day vulnerability in Elastic's Endpoint Detection and Response (EDR) solution allows attackers to bypass security measures , execute malicious code, and cause a system crash (BSOD).

Elastic EDR: Zero-day

These findings come from research by Ashes Cybersecurity. The vulnerability is located in a key component of security software, essentially turning the defensive tool into a weapon against systems.

Specifically, the critical flaw was found in “ elastic-endpoint-driver.sys ”, a kernel driver, signed by Microsoft and developed by Elasticsearch, Inc. This driver is a fundamental part of the Elastic Defend and Elastic Agent security solutions

See also: Hacker sells 15.8 million PayPal Email & Plaintext Passwords

The researcher who discovered the vulnerability presented a four-step attack chain:

  • The attack begins with EDR Bypass , where the attacker uses a custom loader to bypass Elastic's security protections.
  • Once the EDR is bypassed, the attacker can proceed to Remote Code Execution (RCE), to execute malicious code on the system without detection or prevention.
  • Then, Persistence by installing a custom kernel driver that interacts with the vulnerable Elastic driver.
  • Finally, the attacker can trigger a "Privileged Persistent Denial of Service" causing continuous crashes (BSOD), rendering the system inoperable.
Elastic EDR: Zero-day allows malware execution & BSOD

Technical details of the Elastic zero-day vulnerability

The main issue is related to a CWE-476: NULL Pointer Dereference. According to Ashes Cybersecurity, the “elastic-endpoint-driver.sys” driver incorrectly handles memory operations within privileged kernel routines.

See also: Malicious RubyGems and PyPI packages steal data

Under certain conditions, a pointer controlled by user-mode is passed to a kernel function without sufficient checking. If the pointer is null, has been freed, or is corrupted, the kernel attempts to Dereference, leading to a system crash (Blue Screen of Death).

A custom Proof of Concept, consisting of a C-based loader and a custom driver , has already been used to trigger the flaw in a controlled environment. This Proof of Concept first bypasses EDR (Endpoint Detection and Response), loads the custom driver, establishes persistence so that the driver reloads after each reboot, and then interacts with the vulnerable Elastic driver to cause a BSOD (Blue Screen of Death). This essentially demonstrates that the Elastic driver can be manipulated to exhibit malware-like behavior.

The implications of this zero-day vulnerability are severe for businesses that rely on Elastic's security products. A trusted and signed kernel driver can be turned into a dangerous weapon.

See also: Cyberattack on Columbia University - 870,000 Data Stolen

Elastic EDR: Zero-day allows malware execution & BSOD

The discovery and disclosure process for the vulnerability began on June 2, 2025. Disclosure efforts were made through the HackerOne on June 11 and through the Zero Day Initiative (ZDI) on July 29. Following these efforts, an independent disclosure was made on August 16, 2025. The affected product is elastic-endpoint-driver.sys in version 8.17.6, although all subsequent versions are believed to be vulnerable, as no patch has been released. The researcher noted that the vulnerability was discovered during user-mode testing operations, and that his organization, Ashes Cybersecurity Pvt Ltd., is a paid Elastic customer. Until a patch is released, customers remain exposed to this active zero-day threat.

This vulnerability shows how dangerous a defensive tool can become when turned into an offensive weapon. Organizations using Elastic EDR should:

  • to watch closely for patch release,
  • implement compensating controls (e.g. restricting the execution of unauthorized drivers),
  • to enhance anomaly monitoring in kernel-level events.

This incident is also an important reminder: security is never a given, even in the very tools designed to protect us.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS