CVE-2022-4326: Trellix xAgent permission bypass vulnerability
Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4326 vulnerability?
CVE-2022-4326 is an improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows.
How can a local user exploit CVE-2022-4326?
A local user with administrator privileges can exploit CVE-2022-4326 by bypassing the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality.
What is the severity of CVE-2022-4326?
The severity of CVE-2022-4326 is medium.
Which software versions are affected by CVE-2022-4326?
Trellix Endpoint Agent (xAgent) versions prior to V35.31.22 on Windows are affected by CVE-2022-4326.
How to fix CVE-2022-4326?
To fix CVE-2022-4326, you should update Trellix Endpoint Agent (xAgent) to version V35.31.22 or later.