Path Traversal Vulnerability in System Information Reporter from Trellix
CVE-2025-3722

NONE

Key Information:

Vendor

Trellix

Vendor
CVE Published:
26 June 2025

What is CVE-2025-3722?

A path traversal vulnerability exists in the System Information Reporter from Trellix, specifically affecting version 1.0.3 and earlier. This vulnerability allows an authenticated user with high privileges to craft malicious ePO post requests. As a result, this could potentially enable the user to create files anywhere on the filesystem, leading to the risk of overwriting existing files and disclosing sensitive information.

Affected Version(s)

System Information Reporter Windows 1.0.3

References

CVSS V4

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NCIA researchers
.
CVE-2025-3722 : Path Traversal Vulnerability in System Information Reporter from Trellix