Aller au contenu

Fiche vulnérabilité

CVE-2023-3314 : faille élevée Trellix Enterprise Security Manager (CVSS 8.1)

Description

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain elevation of system privileges.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
3 juil. 2023
Dernière mise à jour
25 oct. 2024

Produits concernés

  • Trellix Enterprise Security Manager

Références

Rechercher une autre vulnérabilité dans la base CVE