{"id":"CVE-2026-54000","summary":"osquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processes` table (Windows)","details":"osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the processes table targeting a maliciously crafted process, due to unchecked PEB string lengths in process command-line and current-directory reads. If exploited successfully, this could allow a potential local privilege escalation from standard user to SYSTEM. This issue is fixed in version 5.23.1.","aliases":["GHSA-4r78-6hg6-33gg"],"modified":"2026-08-12T16:41:10.851133Z","published":"2026-07-10T14:51:35.142Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54000.json","unresolved_ranges":[{"extracted_events":[{"fixed":"5.23.1"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-122"]},"references":[{"type":"WEB","url":"https://github.com/osquery/osquery/releases/tag/5.23.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54000.json"},{"type":"ADVISORY","url":"https://github.com/osquery/osquery/security/advisories/GHSA-4r78-6hg6-33gg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54000"},{"type":"FIX","url":"https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246"},{"type":"FIX","url":"https://github.com/osquery/osquery/pull/8934"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/osquery/osquery","events":[{"introduced":"0"},{"fixed":"3d457c412eb0c986b0c37d8903edae8bc9f9e246"}],"database_specific":{"source":"REFERENCES"}}],"versions":["5.23.0","5.22.1","5.22.0","5.21.0","5.20.0","5.19.0","5.18.0","5.17.0","5.16.0","5.15.0","5.14.1","5.14.0","5.13.1","5.13.0","5.12.1","5.12.0","5.11.0","5.10.2","5.10.1","5.10.0","5.9.1","5.9.0","5.8.2","5.8.1","5.8.0","5.7.0","5.6.0","5.5.1","5.5.0","5.4.0","5.3.0","5.2.2","5.2.1","5.2.0","5.1.0","5.0.1","5.0.0","4.9.0","4.8.0","0.0.2","4.7.0","4.6.0","4.5.1","4.5.0","4.4.0","4.3.0","4.2.0","4.1.2","4.1.1","4.1.0","4.0.2","4.0.1","4.0.0","3.3.2","3.3.1","3.3.0","3.2.9","3.2.8","3.2.7","3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","3.1.0","3.0.0","2.11.2","2.11.1","2.11.0","2.10.4","2.10.3","2.10.2","2.10.1","2.10.0","2.9.2","2.9.1","2.9.0","2.8.1","2.8.0","2.7.0","2.6.1","2.6.0","2.5.3","2.5.2","2.5.1","2.5.0","2.4.7","2.4.6","2.4.5","2.4.4","2.4.3","2.4.2","2.4.1","2.4.0","2.3.4","2.3.3","2.3.2","2.3.1","2.3.0","2.2.3","2.2.2","2.2.1","2.2.0","2.1.2","2.1.1","2.1.0","2.0.0","1.8.2","1.8.1","1.8.0","1.7.7","1.7.6","1.7.5","1.7.4","1.7.3","1.7.2","1.7.1","1.7.0","1.6.4","1.6.3","1.6.2","1.6.1","1.6.0","1.5.3","1.5.2","1.5.1","1.5.0","1.4.7","1.4.6","1.4.5","1.4.4","1.4.3","1.4.2","1.4.1","1.4.0","1.3.1","1.3.0","1.2.2","1.2.1","1.2.0","1.1.0","1.0.5","1.0.4","1.0.3","1.0.2","v0.0.1"],"database_specific":{"vanir_signatures":[{"digest":{"function_hash":"228852708779820532786320834819503120482","length":636},"id":"CVE-2026-54000-87e361a3","signature_type":"Function","signature_version":"v1","source":"https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246","target":{"file":"osquery/tables/system/windows/processes.cpp","function":"getProcessCommandLineLegacy"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246","target":{"function":"getProcessPathInfo","file":"osquery/tables/system/windows/processes.cpp"},"deprecated":false,"digest":{"function_hash":"306587940601306112580030435210540487004","length":742},"id":"CVE-2026-54000-f7669778","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246","target":{"file":"osquery/tables/system/windows/processes.cpp"},"deprecated":false,"digest":{"line_hashes":["308447981142363211615985515753655096694","232315947104041886406316091090938485175","314634592002000634925898458983674878137","92311105500033901178883336836487023411","208063912228706891450281498564227138390","66651716933959046862944774162173267595","89234578315553828212101138330780584999","122262961232880432737998836488539864145","6895062439527825342753533470593808033","315361247399661697776431929753831436842","141000154865052482740855173439526373716","41198519730047945622789183238386735324","132053531584013751190090919823165591976","220151174551386121323712572495857980154","270905240626256297592521923558568990732","255587809683293760045875561171589651239","46881228201026150625723437457918000793","247197467486218324662455351189874724308","76490202239689777896791425933957117020","324665787407035585325812862623802451242","82961630910669690687645073568577066436","244188182522411499524449215540225028559","135041797057326685469714268945066859245","22836615563871611569220703371470858316","194080028447130102827395124653681757956","281401315621537078489076989095945051706","336707167467513026736948309981130714434","83337693850768541698276919012131404938","309799315633791389833559431059065988193","317408809212888510464491819030866407568","260076543256415130708597004250377412531","8337832815307951409042840575845075265","220209825340345263745630311540945157114","199511249804544759600499031721147892449","131876094478714020836757363604760200899"],"threshold":0.9},"id":"CVE-2026-54000-f7c21e83","signature_type":"Line"},{"digest":{"function_hash":"78336634327868810944208183988722797997","length":667},"id":"CVE-2026-54000-fcbbc7f1","signature_type":"Function","signature_version":"v1","source":"https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246","target":{"file":"osquery/tables/system/windows/processes.cpp","function":"getProcessCurrentDirectory"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54000.json","vanir_signatures_modified":"2026-08-12T16:41:10Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}