
🚨High - osquery Windows Heap Overflows Enable Local Privilege Escalation to SYSTEM (CVE-2026-54001, CVE-2026-54000) Two heap buffer overflows in osquery on Windows let a local unprivileged attacker escalate to SYSTEM. CVE-2026-54001 is in the Authenticode table: querying a maliciously crafted binary triggers an out-of-bounds write via publisher-info parsing in getOriginalProgramName. CVE-2026-54000 is in the processes table: querying a crafted process triggers an OOB write from unchecked PEB string lengths in command-line and current-directory reads. Because osquery typically runs as SYSTEM, an attacker who plants the malicious binary/process and gets it queried can turn a standard-user foothold into SYSTEM - exactly the kind of agent that's meant to strengthen, not weaken, endpoint security. 👉Upgrade osquery to 5.23.1.
Post summary
The post discloses two local privilege escalation heap overflows in osquery on Windows (CVE‑2026‑54001/54000) and recommends upgrading to version 5.23.1 to mitigate the issue.
