PT-2026-57207 · Squery · Osquery
CVE-2026-54000
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v4.0
7.0
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
osquery versions prior to 5.23.1
Description
On Windows, a local unprivileged attacker can trigger a heap buffer out-of-bounds write when a query is performed on the processes table targeting a maliciously crafted process. This occurs because the software fails to check PEB (Process Environment Block) string lengths during reads of the process command-line and current-directory. Successful exploitation could lead to local privilege escalation from a standard user to SYSTEM.
Recommendations
Update osquery to version 5.23.1.
Exploit
Fix
LPE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Osquery