Trellix
trellix
32 CVEs • 15 products
Products (15)
Click to collapseToggle
Products (15)
Click to collapse
CVEs (32)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) wa...Show more |
1Trellix 1System Information Reporter Jun 17, 2026 Jun 26, 2025 0.0 NONE· v4 5.5 MEDIUM· v3 N/A· v2 A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder. |
1Trellix 1System Information Reporter Jun 17, 2026 Jun 26, 2025 7.2 HIGH· v4 7.1 HIGH· v3 N/A· v2 A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash....Show more |
1Trellix 1System Information Reporter Jun 17, 2026 Jun 26, 2025 0.0 NONE· v4 4.4 MEDIUM· v3 N/A· v2 A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation...Show more |
1Trellix 1Enterprise Security Manager Jun 17, 2026 Nov 29, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user. |
1Trellix 1Enterprise Security Manager Jun 17, 2026 Nov 29, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack...Show more |
1Trellix 1Intrusion Prevention System Manager Jun 17, 2026 Sep 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager. |
1Trellix 1Intrusion Prevention System Manager Jun 17, 2026 Sep 5, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly |
An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute command...Show more |
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into t...Show more |
1Trellix 1Endpoint Security Web Control Jun 17, 2026 Jan 10, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into repor...Show more |
A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the T...Show more |
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding...Show more |
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn...Show more |
1Trellix 1Enterprise Security Manager Jun 17, 2026 Nov 29, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certifi...Show more |
1Trellix 1Application And Change Control Jun 17, 2026 Nov 27, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises ePO servers, prior to version 8.4.0 could lead to an authorised administrator att...Show more |
An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to files that usually require a higher privilege level. This is caused b...Show more |
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of...Show more |
A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission to.
|
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an...Show more |