CVE-2022-3859 Vulnerability Details

  /     /     /  

CVE-2022-3859 Metadata Quick Info

CVE Published: 30/11/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: trellix | Vendor: Trellix | Product: Trellix Agent
Status : PUBLISHED

CVE-2022-3859 Description

An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.

Metrics

CVSS Version: 3.1 | Base Score: 6.7 MEDIUM
Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* HIGH
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: CWE- 427: Uncontrolled Search Path Element
Source: Trellix

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-234
CAPEC Description: CAPEC-234: Hijacking a privileged process


Source: NVD (National Vulnerability Database).