
🚨High - osquery Windows Heap Overflows Enable Local Privilege Escalation to SYSTEM (CVE-2026-54001, CVE-2026-54000) Two heap buffer overflows in osquery on Windows let a local unprivileged attacker escalate to SYSTEM. CVE-2026-54001 is in the Authenticode table: querying a maliciously crafted binary triggers an out-of-bounds write via publisher-info parsing in getOriginalProgramName. CVE-2026-54000 is in the processes table: querying a crafted process triggers an OOB write from unchecked PEB string lengths in command-line and current-directory reads. Because osquery typically runs as SYSTEM, an attacker who plants the malicious binary/process and gets it queried can turn a standard-user foothold into SYSTEM - exactly the kind of agent that's meant to strengthen, not weaken, endpoint security. 👉Upgrade osquery to 5.23.1.
Post summary
Two heap buffer overflows in osquery’s Windows components enable local privilege escalation to SYSTEM; upgrading to 5.23.1 resolves the issue.
