CVE-2023-3438: High severity Trellix Move Windows vulnerability
An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3438?
CVE-2023-3438 is an unquoted Windows search path vulnerability that allows an unauthorized local user to insert arbitrary code into the unquoted service path, leading to privilege escalation and the ability to stop antimalware functionality.
How does CVE-2023-3438 impact the affected software?
CVE-2023-3438 impacts the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe) by allowing an unauthorized local user to exploit the unquoted service path to gain elevated privileges and disable antimalware functionality.
What is the severity of CVE-2023-3438?
CVE-2023-3438 has a severity rating of high, with a CVSS score of 7.8.
How can I fix CVE-2023-3438?
To fix CVE-2023-3438, it is recommended to update to a version of MOVE that is not affected by the vulnerability.
Where can I find more information about CVE-2023-3438?
For more information about CVE-2023-3438, you can visit the following link: [https://kcm.trellix.com/corporate/index?page=content&id=SB10404](https://kcm.trellix.com/corporate/index?page=content&id=SB10404)