# Elastic Stack 6.6.2 and 5.6.16 security update

**URL:** <https://discuss.elastic.co/t/elastic-stack-6-6-2-and-5-6-16-security-update/173180>\
**Category:** Security Announcements\
**Created:** [March 20, 2019, 3:09pm UTC](https://discuss.elastic.co/t/elastic-stack-6-6-2-and-5-6-16-security-update/173180 "2019-03-20T15:09:22Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [March 20, 2019, 3:09pm UTC](https://discuss.elastic.co/t/elastic-stack-6-6-2-and-5-6-16-security-update/173180/1 "2019-03-20T15:09:22Z")

</div>

**Winlogbeat insufficient logging issue (ESA-2019-06)**

Nate Guagenti (@ neu5ron), solutions engineer with Perched Inc. reported an issue in Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.

**Affected Versions**  
Winlogbeat versions before 5.6.16 and 6.6.2

**Solutions and Mitigations:**  
Users should upgrade to Winlogbeat version 6.6.2 or 5.6.16

**CVE ID:** CVE-2019-7613

---

_[View the full topic](https://discuss.elastic.co/t/elastic-stack-6-6-2-and-5-6-16-security-update/173180)._
