CVE-2022-2313: DLL high jacking in Trellix Agent
A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2313?
CVE-2022-2313 is a DLL hijacking vulnerability in the MA Smart Installer for Windows prior to version 5.7.7.
How does CVE-2022-2313 allow attackers to execute arbitrary code?
CVE-2022-2313 allows local users to execute arbitrary code by carefully placing a malicious DLL into the folder where the Smart Installer is being executed.
How can an attacker obtain higher privileges using CVE-2022-2313?
An attacker can obtain higher privileges by exploiting CVE-2022-2313 and executing the malicious code.
What is the severity of CVE-2022-2313?
CVE-2022-2313 has a severity rating of 7.3 (high).
How can I fix the CVE-2022-2313 vulnerability?
To fix the CVE-2022-2313 vulnerability, update the MA Smart Installer to version 5.7.7 or newer.