Elastic response to blog ‘EDR ... Note

Elastic response to blog ‘EDR 0-Day Vulnerability’

Elastic's Information Security team was alerted to an alleged vulnerability in Elastic Defend on August 16, 2025. Following a comprehensive investigation, Elastic's Security Engineering team found no evidence to support claims of a vulnerability bypassing EDR monitoring or enabling remote code execution. The researcher's demonstration of triggering a crash or Blue Screen of Death in the Elastic Endpoint driver was performed from another kernel driver. Elastic remains committed to investigating the matter further and will update customers and the community if any genuine security issues are identified. They are requesting that anyone with detailed information demonstrating the ability to crash the driver from an unprivileged process share it with them. Elastic reserves the right to release or not release any features or functionality discussed. Features or functionality not currently available may not be delivered as planned, or at all. The company prioritizes customer security and transparency. This statement serves to inform stakeholders about their findings and ongoing efforts.