osquery susceptible to DLL search order hijacking of zlib1.dll
Vulnerability Description
osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. This is fixed in version 4.4.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-11081
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/osquery/osquery/security/advisories/GHSA-2xwp-8fv7-c5pm
- https://github.com/osquery/osquery/issues/6426
- https://github.com/osquery/osquery/pull/6433
- https://github.com/osquery/osquery/commit/4d4957f12a6aa0becc9d01d9f97061e1e3d809c5
- https://github.com/osquery/osquery/releases/tag/4.4.0
Affected Vendor
osquery
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.