Impact
Tanium Enforce contains an unauthorized code execution vulnerability that allows an attacker to run arbitrary code. This flaw is identified as CWE‑78 and can potentially compromise system confidentiality, integrity, and availability by enabling malicious operations. The impact is a full loss of control over affected systems if exploited.
Affected Systems
The vulnerability affects Tanium Enforce. Specific affected product versions are not disclosed in the available data.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity, although an EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly provided in the advisory; based on the nature of the flaw it is inferred that it could be exploitable remotely or locally, depending on the configuration of Enforce. Without a publicly disclosed exploitation technique, the likelihood remains uncertain but the high CVSS justifies proactive mitigation.
OpenCVE Enrichment