PT-2020-12538 · Facebook · Osquery

Smjert

·

Published

2020-07-10

·

Updated

2023-01-20

·

CVE-2020-11081

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions osquery versions prior to 4.4.0
Description The issue allows for a privilege escalation. If a Windows system has a PATH containing a user-writable directory, a local user can create a zlib1.dll DLL that osquery will attempt to load, enabling local escalation because osquery runs with elevated privileges.
Recommendations For versions prior to 4.4.0, update to version 4.4.0 to resolve the issue. As a temporary workaround, consider restricting the PATH environment variable to exclude user-writable directories until the update can be applied.

Exploit

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2020-11081
GHSA-2XWP-8FV7-C5PM

Affected Products

Osquery