First published: Mon Mar 13 2023(Updated: )
A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack
Credit: trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Advanced Threat Defense | >=4.0<=4.14.2 | |
Trellix Intelligent Sandbox | =5.0 | |
Trellix Intelligent Sandbox | =5.2 |
To remediate this issue, customers running ATD/IS 5.2.0 or earlier must go to the Product Downloads site https://www.trellix.com/en-us/downloads/my-products.html and download the applicable product update/hotfix file:
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0978 is a command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier.
McAfee Advanced Threat Defense version 4.0 to 4.14.2 is affected by CVE-2023-0978.
Trellix Intelligent Sandbox versions 5.0 and 5.2 are affected by CVE-2023-0978.
CVE-2023-0978 has a severity rating of 6.7, which is considered medium.
To fix CVE-2023-0978, it is recommended to upgrade to a version of Trellix Intelligent Sandbox CLI that is not affected by the vulnerability.