← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 18, 2026 · 20:23via CVEFeed

CVE-2026-57223 - Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalation

Brief

CVE ID : CVE-2026-57223

Published : Sept. 18, 2026, 8:23 p. m.

  • 33 minutes ago

Description : Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.

  • 17 and 8.
  • 6, the Windows service installation and parameter-update logic in src/win32-service. c can pass an unquoted service ImagePath to CreateServiceA.

When Suricata is installed below a path containing spaces and an earlier path component is writable by a local low-privileged attacker, Windows can execute an attacker-controlled program as LocalSystem, resulting in local privilege escalation. This issue is fixed in versions 8.

  • 6 and 7.
  • 17.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→