CVE-2026-54000Patch

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the processes table targeting a maliciously crafted process, due to unchecked PEB string lengths in process command-line and current-directory reads. If exploited successfully, this could allow a potential local privilege escalation from standard user to SYSTEM. This issue is fixed in version 5.23.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-10: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 107-10
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - osquery Windows Heap Overflows Enable Local Privilege Escalation to SYSTEM (CVE-2026-54001, CVE-2026-54000) Two heap buffer overflows in osquery on Windows let a local unprivileged attacker escalate to SYSTEM. CVE-2026-54001 is in the Authenticode table: querying a maliciously crafted binary triggers an out-of-bounds write via publisher-info parsing in getOriginalProgramName. CVE-2026-54000 is in the processes table: querying a crafted process triggers an OOB write from unchecked PEB string lengths in command-line and current-directory reads. Because osquery typically runs as SYSTEM, an attacker who plants the malicious binary/process and gets it queried can turn a standard-user foothold into SYSTEM - exactly the kind of agent that's meant to strengthen, not weaken, endpoint security. 👉Upgrade osquery to 5.23.1.

    Post summary

    The post discloses two local privilege escalation heap overflows in osquery on Windows (CVE‑2026‑54001/54000) and recommends upgrading to version 5.23.1 to mitigate the issue.

    00010122
    246 followersView on X

Explore more