Impact
The vulnerability describes improper access controls in the Tanium Comply product, allowing users who lack appropriate privileges to gain unauthorized access to privileged functions. This could lead to unauthorized disclosure, modification, or destruction of information and elevation of user privileges. The exact attack vector is not detailed in the official description, so the exploitation path remains unclear but likely requires authenticated interactions with the Comply service.
Affected Systems
The Tanium Comply product is affected. No specific version information is provided; organizations should verify the installed version against vendor advisories.
Risk and Exploitability
With a CVSS score of 5.4, the vulnerability is considered moderate. The EPSS score is not available, and it is not listed in CISA's KEV catalog, indicating no publicly known exploitation at this time. The risk is moderate, and the likelihood of exploitation remains uncertain, particularly due to the lack of details on the attack vector. However, the moderate severity suggests that any exploitation could have meaningful impact on confidentiality or integrity if successful.
OpenCVE Enrichment