PT-2026-57208 · Squery · Osquery

CVE-2026-54001

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions osquery versions prior to 5.23.1
Description On Windows, a local unprivileged attacker can trigger a heap buffer out-of-bounds write when a query is performed on the authenticode table targeting a maliciously crafted binary. This occurs during the parsing of publisher information within the getOriginalProgramName() function. Successful exploitation may lead to local privilege escalation from a standard user to SYSTEM.
Recommendations Update osquery to version 5.23.1.

Exploit

Fix

LPE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54001
GHSA-HR28-JVPX-68CX

Affected Products

Osquery