# ESA-2025-12 Detail Questions

**URL:** <https://discuss.elastic.co/t/esa-2025-12-detail-questions/381320>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [August 25, 2025, 6:29pm UTC](https://discuss.elastic.co/t/esa-2025-12-detail-questions/381320 "2025-08-25T18:29:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Post date:** [August 25, 2025, 6:29pm UTC](https://discuss.elastic.co/t/esa-2025-12-detail-questions/381320/1 "2025-08-25T18:29:42Z")

</div>

Per [Beats (Windows Installer) 8.18.6, 8.19.3, 9.0.6, & 9.1.0 Security Update (ESA-2025-12)](https://discuss.elastic.co/t/beats-windows-installer-8-18-6-8-19-3-9-0-6-9-1-0-security-update-esa-2025-12/380558) ,

### Affected Configurations:

The issue only affects Beats when installed through the install-service script for Windows. Example when installing [Filebeat](https://www.elastic.co/docs/reference/beats/filebeat/filebeat-installation-configuration#installation)using `.\install-service-filebeat.ps1`.

Can anyone confirm that if we don’t install via the above method, but instead install via msiexec command, does that mean this vulnerability does NOT apply? How could we tell for sure?

---

<div class="post-metadata">

**Author:** ![HenrikR](https://avatars.discourse-cdn.com/v4/letter/h/3d9bf3/32.png) [@HenrikR](https://discuss.elastic.co/u/HenrikR)\
**Post date:** [August 28, 2025, 9:49am UTC](https://discuss.elastic.co/t/esa-2025-12-detail-questions/381320/2 "2025-08-28T09:49:40Z")

</div>

Is there any ETA of the maintenance update for lower versions than 9.1.2?
