Skip to content

Commit 0771b3b

Browse files
natasha-moore-elasticbenironsidegabriellandau
authored
Apply suggestions from code review
Co-authored-by: Benjamin Ironside Goldstein <[email protected]> Co-authored-by: Gabriel Landau <[email protected]>
1 parent 155b033 commit 0771b3b

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

release-notes/elastic-security/index.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -126,7 +126,7 @@ To check for security updates, go to [Security announcements for the Elastic sta
126126
## 9.1.7 [elastic-security-9.1.7-release-notes]
127127

128128
### Features and enhancements [elastic-security-9.1.7-features-enhancements]
129-
* Improves the reliability of Cloud Security Posture (CSP) data by automatically upgrading outdated Misconfiguration and Vulnerabilities data views to the correct versions [#238547]({{kib-pull}}238547).
129+
* Improves the reliability of Cloud Security Posture (CSP) data by automatically upgrading outdated Misconfiguration and Vulnerabilities data views to the correct versions [#238547]({{kib-pull}}238547).
130130
* Adds more {{elastic-defend}} options to the {{ls}} output, allowing for finer control.
131131
* Improves the accuracy of thread CPU usage reported in {{elastic-defend}} metrics documents.
132132

@@ -140,9 +140,9 @@ To check for security updates, go to [Security announcements for the Elastic sta
140140
* Fixes an {{elastic-defend}} issue on Linux by preventing unnecessary locking within malware protection to avoid invalid watchdog firings.
141141
* Fixes issues that could sometimes cause crashes of the {{elastic-defend}} user-mode process on very busy Windows systems.
142142
* Fixes multiple {{elastic-defend}} issues in malware protection for Linux where a deadlock could sometimes occur when containers and autofs were both active.
143-
* Fixes an {{elastic-defend}} issue on Windows which could allow a low-privilege attacker to delete arbitrary files on the system and potentially escalate privileges to SYSTEM. Windows 11 24H2 includes changes which make this issue harder to exploit.
143+
* Fixes CVE-2025-37735 ([ESA-2025-23](https://discuss.elastic.co/t/elastic-defend-8-19-6-9-1-6-and-9-2-0-security-update-esa-2025-23/383272)) in {{elastic-defend}} on Windows which could allow a low-privilege attacker to delete arbitrary files on the system and potentially escalate privileges to SYSTEM. Windows 11 24H2 includes changes which make this issue harder to exploit.
144144
* Fixes an {{elastic-defend}} bug in Linux event collection where some long-running processes were not enriched.
145-
* Fixes an issue in {{elastic-defend}} that could cause the `get-file` and `execute` response actions to start failing after many are issued with a single running instance of {{elastic-defend}}.
145+
* Fixes an {{elastic-defend}} issue that could cause the `get-file` and `execute` response actions to fail after many were issued with a single running instance of {{elastic-defend}}.
146146

147147

148148
## 9.1.6 [elastic-security-9.1.6-release-notes]

0 commit comments

Comments
 (0)