Wiz Agents & Workflows are here

CVE-2020-11081
OSQuery vulnerability analysis and mitigation

Overview

CVE-2020-11081 is a privilege escalation vulnerability affecting osquery versions before 4.4.0. The vulnerability was discovered in May 2020 and patched in June 2020. The issue occurs when osquery attempts to load zlib1.dll on Windows systems, where if a system is configured with a PATH containing a user-writable directory, a local user could exploit this to achieve privilege escalation (GitHub Advisory).

Technical details

The vulnerability was introduced through OpenSSL's dependency on zlib for SSL/TLS compression. On Windows systems, OpenSSL would attempt to load zlib1.dll as a dynamic library, which could potentially be loaded from an insecure location. Since osquery runs with elevated privileges, this DLL search order hijacking vulnerability could be exploited for privilege escalation. The issue was particularly concerning because compression in SSL/TLS has been proven to potentially lead to information leaks (GitHub PR).

Impact

If successfully exploited, an attacker could achieve local privilege escalation to NT AUTHORITY\SYSTEM level access on affected Windows systems. This occurs when osquery service, running with elevated privileges, loads a malicious zlib1.dll from a user-writable directory in the system's PATH (GitHub Issue).

Mitigation and workarounds

The vulnerability was patched in osquery version 4.4.0 by disabling OpenSSL compression support entirely. For systems unable to update immediately, the recommended workaround is to ensure system PATH directories are not user-writable, restricting PATH writability to administrators and similarly-privileged accounts (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related OSQuery vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-1887CRITICAL9.1
  • OSQueryOSQuery
  • osquery
NoYesMar 13, 2020
CVE-2020-11081HIGH8.2
  • OSQueryOSQuery
  • osquery
NoYesJul 10, 2020
CVE-2019-3567HIGH8.1
  • OSQueryOSQuery
  • cpe:2.3:a:linuxfoundation:osquery
NoYesJun 03, 2019
CVE-2018-6336HIGH7.8
  • OSQueryOSQuery
  • cpe:2.3:a:linuxfoundation:osquery
NoYesDec 31, 2018
CVE-2020-26273MEDIUM5.2
  • OSQueryOSQuery
  • cpe:2.3:a:linuxfoundation:osquery
NoYesDec 16, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management