Impact
The vulnerability is an improper access control flaw in Tanium Threat Response that can allow an attacker to bypass expected authorization checks. The primary impact is the potential for an attacker to gain unauthorized access or elevate privileges within the system, which could lead to unauthorized data access, modification, or other malicious activity. The weakness is classified under CWE-862, indicating that the system fails to enforce appropriate access permissions.
Affected Systems
Tanium Threat Response is affected. No specific version information is provided, so all installations of Tanium Threat Response are potentially impacted until a vendor-released fix or mitigation strategy is applied.
Risk and Exploitability
The CVSS score of 3.8 indicates low severity, and the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote via the Threat Response interface or API, but the description does not explicitly specify the required conditions or environment for exploitation. Therefore, the risk is considered low but not negligible, and monitoring for unauthorized access attempts is recommended.
OpenCVE Enrichment