漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
osquery susceptible to DLL search order hijacking of zlib1.dll
Vulnerability Description
osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. This is fixed in version 4.4.0.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N
Vulnerability Type
流程控制
Vulnerability Title
Facebook osquery 代码问题漏洞
Vulnerability Description
osquery是一款由SQL驱动的操作系统检测、监视和分析框架。 Facebook osquery 4.4.0之前版本中存在安全漏洞。本地攻击者可利用该漏洞提升权限。
CVSS Information
N/A
Vulnerability Type
N/A