CVE-2022-3859
Last modified
CVE-2022-3859 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there. . EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trellix | Agent | < 5.7.8 |
References
- https://kcm.trellix.com/corporate/index?page=content&id=SB10391Patch, Vendor Advisory
- https://kcm.trellix.com/corporate/index?page=content&id=SB10391Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3859?
How severe is CVE-2022-3859?
How do I fix CVE-2022-3859?
Are you affected by CVE-2022-3859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
