๐Ÿ” CVE Alert

CVE-2026-57223

HIGH 7.0

Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalation

CVSS Score
7.0
EPSS Score
0.0%
EPSS Percentile
0th

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an unquoted service ImagePath to CreateServiceA. When Suricata is installed below a path containing spaces and an earlier path component is writable by a local low-privileged attacker, Windows can execute an attacker-controlled program as LocalSystem, resulting in local privilege escalation. This issue is fixed in versions 8.0.6 and 7.0.17.

CWE CWE-428
Vendor oisf
Product suricata
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for oisf suricata

Be the first to know when new high vulnerabilities affecting oisf suricata are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

OISF / suricata
>= 8.0.0, < 8.0.6 < 7.0.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OISF/suricata/security/advisories/GHSA-jh8w-wf3f-58jp github.com: https://github.com/OISF/suricata/pull/15676 github.com: https://github.com/OISF/suricata/commit/0dad38fff024b4fec9bc8144d8b94dbca39aac2e github.com: https://github.com/OISF/suricata/commit/2b924d47cc51d0b7760cda3519f2c04a2f65ea38 github.com: https://github.com/OISF/suricata/commit/ac1b3cc1ef3af65ce92da28261d445167eb8234d github.com: https://github.com/OISF/suricata/releases/tag/suricata-7.0.17 github.com: https://github.com/OISF/suricata/releases/tag/suricata-8.0.6 redmine.openinfosecfoundation.org: https://redmine.openinfosecfoundation.org/issues/8600