CVE-2020-11081

MEDIUM

osquery <4.4.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. This is fixed in version 4.4.0.

References (5)

Core 5
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/osquery/osquery/issues/6426
Patch, Third Party Advisory x_refsource_misc
https://github.com/osquery/osquery/pull/6433
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/osquery/osquery/releases/tag/4.4.0

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 16.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N

Details

CWE
CWE-114 CWE-426
Status published
Products (1)
linuxfoundation/osquery < 4.4.0
Published Jul 10, 2020
Tracked Since Feb 18, 2026