An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: trellix
Published: 2022-11-30T08:29:29.242Z
Updated: 2025-04-23T19:28:30.917Z
Reserved: 2022-11-04T09:51:23.470Z
Link: CVE-2022-3859

Updated: 2024-08-03T01:20:58.790Z

Status : Modified
Published: 2022-11-30T09:15:08.977
Modified: 2024-11-21T07:20:22.817
Link: CVE-2022-3859

No data.