CVE-2022-3859
Last modified
CVE-2022-3859 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there. . EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trellix | Agent | < 5.7.8 |
References
- https://kcm.trellix.com/corporate/index?page=content&id=SB10391Patch, Vendor Advisory
- https://kcm.trellix.com/corporate/index?page=content&id=SB10391Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3859?
How severe is CVE-2022-3859?
How do I fix CVE-2022-3859?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-38576Interview Management System v1.0 was discovered to contain a…7.2
- CVE-2022-38577ProcessMaker before v3.5.4 was discovered to contain insecur…8.8
- CVE-2022-3858The Floating Chat Widget: Contact Chat Icons, Telegram Chat,…7.2
- CVE-2022-38580Zalando Skipper v0.13.236 is vulnerable to Server-Side Reque…9.8
- CVE-2022-38582Incorrect access control in the anti-virus driver wsdkd.sys …6.5
- CVE-2022-38583On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which ar…7.8
- CVE-2022-38594Church Management System v1.0 was discovered to contain a SQ…7.2
- CVE-2022-38595Church Management System v1.0 was discovered to contain a SQ…7.2
- CVE-2022-38599Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2…6.5
- CVE-2022-3860The Visual Email Designer for WooCommerce WordPress plugin b…8.8
- CVE-2022-38600Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via v…5.5
- CVE-2022-38604Wacom Driver 6.3.46-1 for Windows and lower was discovered t…7.3
Are you affected by CVE-2022-3859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
