Impact
Tanium has identified a vulnerability that permits an attacker to execute arbitrary code without proper authorization within the Comply component. The flaw, catalogued as CWE-1336, undermines the integrity and confidentiality of the system and based on the description, it is inferred that the flaw could allow unauthorized access to sensitive data or control over the system.
Affected Systems
The security issue impacts Tanium Comply installations. No specific version range is disclosed, so any installation of the product is likely vulnerable until a vendor‑supplied fix is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2, indicating a high level of risk. The EPSS score is not available, and the issue is not listed in CISA's KEV catalog. Based on the description, it is inferred that an attacker could exploit the flaw with elevated privileges if they can interact with the vulnerable component. Attack details are not publicly documented, so the exact vector remains unclear, but the potential for serious compromise warrants prompt remediation.
OpenCVE Enrichment