CVE-2023-0400: High severity trellix data loss prevention vulnerability
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-0400?
CVE-2023-0400 is a protection bypass vulnerability in DLP for Windows 11.9.x.
How does CVE-2023-0400 work?
CVE-2023-0400 allows a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client, while loading from a local drive is correctly prevented.
Is Trellix Data Loss Prevention affected by CVE-2023-0400?
Yes, versions of Trellix Data Loss Prevention prior to 11.9 are affected by CVE-2023-0400.
How can I fix CVE-2023-0400?
You can address CVE-2023-0400 by updating Trellix Data Loss Prevention to version 11.10.0.
What is the severity of CVE-2023-0400?
CVE-2023-0400 has a severity score of 8.2 (high).