CVE-2023-0221: Medium severity trellix application and change control vulnerability
Published Jan 13, 2023
·Updated
Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program.
Affected Software
1 affected component
McAfee Application and Change Control<8.3.4
Event History
Jan 13, 2023
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the product security bypass vulnerability in ACC?
The vulnerability ID for the product security bypass vulnerability in ACC is CVE-2023-0221.
2
What is the severity of CVE-2023-0221?
The severity of CVE-2023-0221 is medium with a severity value of 4.4.
3
What software versions are affected by CVE-2023-0221?
The ACC versions prior to 8.3.4 are affected by CVE-2023-0221.
4
How does the vulnerability in ACC allow a locally logged-in attacker to bypass execution controls?
The vulnerability in ACC allows a locally logged-in attacker with administrator privileges to bypass execution controls using the utilman program.
5
How can I fix the vulnerability in ACC?
To fix the vulnerability in ACC, update to version 8.3.4 or later.