{"id":"CVE-2026-54001","summary":"osquery: Heap buffer overflow via `authenticode` table (Windows)","details":"osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the authenticode table targeting a maliciously crafted binary, due to publisher information parsing in getOriginalProgramName. If exploited successfully, this could allow a potential local privilege escalation from standard user to SYSTEM. This issue is fixed in version 5.23.1.","aliases":["GHSA-hr28-jvpx-68cx"],"modified":"2026-08-12T16:41:11.106652Z","published":"2026-07-10T14:49:18.318Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54001.json","unresolved_ranges":[{"extracted_events":[{"fixed":"5.23.1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/osquery/osquery/releases/tag/5.23.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54001.json"},{"type":"ADVISORY","url":"https://github.com/osquery/osquery/security/advisories/GHSA-hr28-jvpx-68cx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54001"},{"type":"FIX","url":"https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54"},{"type":"FIX","url":"https://github.com/osquery/osquery/pull/8923"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/osquery/osquery","events":[{"introduced":"0"},{"fixed":"59a808cda96d5a089cf6ec147efe152459284d54"}],"database_specific":{"source":"REFERENCES"}}],"versions":["5.23.0","5.22.1","5.22.0","5.21.0","5.20.0","5.19.0","5.18.0","5.17.0","5.16.0","5.15.0","5.14.1","5.14.0","5.13.1","5.13.0","5.12.1","5.12.0","5.11.0","5.10.2","5.10.1","5.10.0","5.9.1","5.9.0","5.8.2","5.8.1","5.8.0","5.7.0","5.6.0","5.5.1","5.5.0","5.4.0","5.3.0","5.2.2","5.2.1","5.2.0","5.1.0","5.0.1","5.0.0","4.9.0","4.8.0","0.0.2","4.7.0","4.6.0","4.5.1","4.5.0","4.4.0","4.3.0","4.2.0","4.1.2","4.1.1","4.1.0","4.0.2","4.0.1","4.0.0","3.3.2","3.3.1","3.3.0","3.2.9","3.2.8","3.2.7","3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","3.1.0","3.0.0","2.11.2","2.11.1","2.11.0","2.10.4","2.10.3","2.10.2","2.10.1","2.10.0","2.9.2","2.9.1","2.9.0","2.8.1","2.8.0","2.7.0","2.6.1","2.6.0","2.5.3","2.5.2","2.5.1","2.5.0","2.4.7","2.4.6","2.4.5","2.4.4","2.4.3","2.4.2","2.4.1","2.4.0","2.3.4","2.3.3","2.3.2","2.3.1","2.3.0","2.2.3","2.2.2","2.2.1","2.2.0","2.1.2","2.1.1","2.1.0","2.0.0","1.8.2","1.8.1","1.8.0","1.7.7","1.7.6","1.7.5","1.7.4","1.7.3","1.7.2","1.7.1","1.7.0","1.6.4","1.6.3","1.6.2","1.6.1","1.6.0","1.5.3","1.5.2","1.5.1","1.5.0","1.4.7","1.4.6","1.4.5","1.4.4","1.4.3","1.4.2","1.4.1","1.4.0","1.3.1","1.3.0","1.2.2","1.2.1","1.2.0","1.1.0","1.0.5","1.0.4","1.0.3","1.0.2","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54001.json","vanir_signatures_modified":"2026-08-12T16:41:11Z","vanir_signatures":[{"id":"CVE-2026-54001-08767270","signature_type":"Line","signature_version":"v1","source":"https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54","target":{"file":"tests/integration/tables/authenticode.cpp"},"deprecated":false,"digest":{"line_hashes":["283886038157249001085904951270182065068","285873272593745641487616476674256273689","138499954941120660949527084456780643227","23400284557401938507561993011713184143","180287355814760970901333659961095352739"],"threshold":0.9}},{"id":"CVE-2026-54001-64ead62c","signature_type":"Function","signature_version":"v1","source":"https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54","target":{"file":"tests/integration/tables/authenticode.cpp","function":"TEST_F"},"deprecated":false,"digest":{"function_hash":"237220395582663748917960012670782508566","length":108}},{"deprecated":false,"digest":{"function_hash":"118683739597154858346068228729799647877","length":1184},"id":"CVE-2026-54001-9cc401be","signature_type":"Function","signature_version":"v1","source":"https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54","target":{"file":"osquery/tables/system/windows/authenticode.cpp","function":"getOriginalProgramName"}},{"deprecated":false,"digest":{"line_hashes":["123652659234302333876283263177204890259","178775983326812485869585408728749357244","208358014525042409148746933622351792677","143275159745711910960043008628816811169","265839029446489806182030292480903984331","64342131187373583749493940121963538145","313341974783317416158119323137563980158","218614348098201550253491270365511480535","40130054755274292906746795992936696424","72211739438395677100613869155455943545","79136154244196730329043813515680289956","184076681608397273316045238945996621705","55799888736442402196515809540253642164","178040637249566550216340368184746358151","74874625960100234340570681432504251067","69244498338284723965107567650313591425","334686492746056151081654360398532174192","169261948339119312367306767682085841997","257658083653612996960136022587464412332","146767302623013860296348035460980498944","267152507593443361323651565350511226008","137226579793062214773144867186430769893","161094030227436629289940526251488995854","312262304852652255258814091507186117656","150574127307128030955228309324355298009","6347561236917925103147752961706612354","61380374525772020355737143315826499191","74874625960100234340570681432504251067","69244498338284723965107567650313591425","149414358778412747476886541465311037330","257033988876825129680811194625687593320","145915118280517480522362023870584038275","252797944462312080472285132141228457250","175432925302650715629917107983496099841","304864215130903309527420008003072208389","222250033818197274169401316921735522281","158026541226986460768896770407331225459","237927133398736812496393287882746860023"],"threshold":0.9},"id":"CVE-2026-54001-b303b16a","signature_type":"Line","signature_version":"v1","source":"https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54","target":{"file":"osquery/tables/system/windows/authenticode.cpp"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}