6
CVE-2022-4326
- EPSS 0.01%
- Veröffentlicht 16.12.2022 16:15:25
- Zuletzt bearbeitet 21.11.2024 07:35:03
- Quelle trellixpsirt@trellix.com
- Teams Watchlist Login
- Unerledigt Login
Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trellix ≫ Endpoint Security Version < 35.31.22
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.01% | 0.013 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6 | 0.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
|
trellixpsirt@trellix.com | 5.5 | 1.1 | 4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:N/A:H
|
CWE-281 Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.