PT-2020-12538 · Facebook · Osquery

·

CVE-2020-11081

·

Published

2020-07-10

·

Updated

2023-01-20

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions osquery versions prior to 4.4.0
Description The issue allows for a privilege escalation. If a Windows system has a PATH containing a user-writable directory, a local user can create a zlib1.dll DLL that osquery will attempt to load, enabling local escalation because osquery runs with elevated privileges.
Recommendations For versions prior to 4.4.0, update to version 4.4.0 to resolve the issue. As a temporary workaround, consider restricting the PATH environment variable to exclude user-writable directories until the update can be applied.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11081
GHSA-2XWP-8FV7-C5PM

Affected Products

Osquery