Elastic has disclosed a serious security flaw affecting Elastic Defend for Windows , leaving open the possibility that attackers could gain full administrator privileges on vulnerable systems.

The issue, tracked as CVE-2025-37735, concerns improper privilege management within the Defend service, which runs with SYSTEM – the highest level of access in Windows.
What causes vulnerability?
The vulnerability is in the way Elastic Defend handles file permissions on Windows hosts. Because the Defend service runs with SYSTEM privileges, an attacker with local access could exploit the flaw to delete or modify critical operating system files.
See also: Landfall spyware targeted Samsung Galaxy phones
In some scenarios, this vulnerability could be exploited for local , privilege escalationallowing an unauthorized user to gain complete control of the device.
In practice, this means that an attacker who already has limited access—e.g., through a regular user account—can turn it into administrator-level or even system-level access.
Why is it important?
Elastic confirms that the issue affects Elastic Defend versions up to 8.19.5, as well as versions 9.0.0 through 9.1.5, on various Windows operating system variants.
The vulnerability has been given a CVSS v3.1 severity rating of 7.0, classified as High. Although it requires local access —meaning the attacker must already be on the network or device—the lack of user interaction makes the vulnerability particularly attractive for attacks within organizations.
For example, a malicious employee or an attacker who has infiltrated via phishing could exploit the flaw to escalate their privileges and gain full control of the endpoint.

Impact on business environments
In corporate infrastructures, Elastic Defend is widely used as an detection and endpoint (EDR) response mechanism . If this tool – intended to protect the system – becomes the target of an exploit, then the attacker can bypass the company's own security systems
See also: Amazon WorkSpaces for Linux: Vulnerability allows credential extraction
This creates a dangerous "bridge" between ordinary users and system privileges, allowing persistence and lateral movement to other devices.
Cybersecurity experts point out that such vulnerabilities are often used as a second stage in complex ransomware or APT (Advanced Persistent Threats) attacks, where the attacker aims to control the security infrastructure before launching the attack.
The available updates
Elastic reacted quickly, releasing patched versions that resolve the issue:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- 8.19.6
- 9.1.6
- 9.2.0
The new versions include fixes to the file permissions mechanism and enhanced security policies that prevent critical files from being deleted or modified by users without administrator rights.
For organizations that cannot upgrade immediately, Elastic recommends interim measures. Specifically, Windows 11 24H2 incorporates architectural changes that make exploiting the vulnerability significantly more difficult, acting as an interim protection solution.
What should administrators do?
IT administrators are urged to prioritize updating Elastic Defend, as delay may leave critical endpoints exposed.
In case the upgrade is not immediately possible:
- Consider upgrading your operating system to Windows 11 24H2 or later.
- Implement access control policies (ACLs) to restrict local users.
- Monitor Elastic Security logs for suspicious file deletion or modification actions.

Those who maintain older versions of Windows without a scheduled upgrade should include this patch in their cybersecurity plan as a priority.
See also: Malicious npm packages contain Vidar infostealer
The disclosure of CVE-2025-37735 is a reminder that even security tools can become targets if they are not regularly updated.
Elastic's quick response is encouraging, but the responsibility also lies with organizations who must ensure that their systems are running the latest versions.
In a threat landscape where attacks evolve daily, proactive security is no longer an option — it's a necessity.
