# APM Server (Windows Installer) 8.16.3, 8.17.1 Security Update (ESA-2025-01)

**URL:** https://discuss.elastic.co/t/apm-server-windows-installer-8-16-3-8-17-1-security-update-esa-2025-01/380557
**Category:** Security Announcements
**Created:** [July 29, 2025, 11:30pm UTC](https://discuss.elastic.co/t/apm-server-windows-installer-8-16-3-8-17-1-security-update-esa-2025-01/380557 "2025-07-29T23:30:19Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![Bryan\_Garcia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_garcia/32/148179_2.png) [@Bryan\_Garcia](https://discuss.elastic.co/u/Bryan_Garcia)
#### Post date: [July 29, 2025, 11:30pm UTC](https://discuss.elastic.co/t/apm-server-windows-installer-8-16-3-8-17-1-security-update-esa-2025-01/380557/1 "2025-07-29T23:30:19Z")

</div>

#### APM Server Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows Installer (ESA-2025-01)

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.

### Affected Versions:

APM Server version up to and including 8.16.2, and up to and including 8.17.0.

### Affected Configurations:

The issue only affects APM Server when installed through the install-service script for Windows.

### Solutions and Mitigations:

The issue is resolved in version 8.16.3 and 8.17.1.

**Severity** : CVSSv3.1: 7.0 (High) - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

**CVE ID** : CVE-2025-0712

\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_

### Change log

2025-08-21: Updated wording on the “Affected Configurations” to clearly state this is caused by the Windows install script.
