Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75q5-4hc3-3q65

Опубликовано: 30 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.

An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.

EPSS

Процентиль: 40%
0.00179
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 6.7
nvd
около 3 лет назад

An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.

EPSS

Процентиль: 40%
0.00179
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427