Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3859

Опубликовано: 30 нояб. 2022
Источник: nvd
CVSS3: 6.7
EPSS Низкий

Описание

An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trellix:agent:*:*:*:*:windows:*:*:*
Версия до 5.7.8 (исключая)

EPSS

Процентиль: 39%
0.00179
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 6.7
github
около 3 лет назад

An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.

EPSS

Процентиль: 39%
0.00179
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427