Aller au contenu

Fiche vulnérabilité

CVE-2023-0975 : faille élevée trellix agent (CVSS 7.8)

Description

A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
3 avr. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • trellix agent

Références

Rechercher une autre vulnérabilité dans la base CVE