"-Synchronized-Data."

This commit is contained in:
CVE Team 2020-07-10 19:01:32 +00:00
parent 1e1c02f7e1
commit 3deeabd018
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743

View File

@ -35,7 +35,7 @@
"description_data": [
{
"lang": "eng",
"value": "osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. \n\nThis is fixed in version 4.4.0."
"value": "osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. This is fixed in version 4.4.0."
}
]
},