Command Injection Vulnerability in Trellix TA for macOS
CVE-2023-0976

7.8HIGH

Key Information:

Vendor
Trellix
Vendor
CVE Published:
7 June 2023

Summary

A command injection vulnerability exists in Trellix TA for macOS versions prior to 5.7.9, allowing local users to place a malicious file into the /Library/Trellix/Agent/bin/ directory. This malicious file can be executed when the TA deployment feature is triggered from within the System Tree, potentially leading to unauthorized file actions or system compromise.

Affected Version(s)

Trellix Agent MacOS 5.7.8

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Scheblein
.