CVE-2019-3567
HIGHosquery < 3.4.0 - Unauthenticated Privilege Escalation via Hard Link Attack on Extensions Load Path
Title source: llmDescription
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those circumstances osquery will load said malicious executable with SYSTEM permissions. The solution is to migrate installations to the 'Program Files' directory on Windows which restricts unprivileged write access. This issue affects osquery prior to v3.4.0.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.facebook.com/security/advisories/cve-2019-3567
Scores
CVSS v3
8.1
EPSS
0.0043
EPSS Percentile
62.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-284
CWE-59
Status
published
Products (1)
linuxfoundation/osquery
< 3.4.0
Published
Jun 03, 2019
Tracked Since
Feb 18, 2026