An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: trellix
Published: 2022-11-30T08:29:29.242Z
Updated: 2024-08-03T01:20:58.790Z
Reserved: 2022-11-04T09:51:23.470Z
Link: CVE-2022-3859
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-11-30T09:15:08.977
Modified: 2024-11-21T07:20:22.817
Link: CVE-2022-3859
Redhat
No data.