CVE-2023-3665: Code Injection
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3665?
CVE-2023-3665 is a code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier.
How does CVE-2023-3665 affect Trellix ENS?
CVE-2023-3665 allows a local user to disable the ENS AMSI component via environment variables, leading to denial of service and/or the execution of arbitrary code.
What is the severity of CVE-2023-3665?
CVE-2023-3665 has a severity rating of 7.8 (high).
How can I fix CVE-2023-3665?
To fix CVE-2023-3665, update Trellix ENS to a version later than 10.7.0 April 2023 release.
Where can I find more information about CVE-2023-3665?
More information about CVE-2023-3665 can be found at the following link: [https://kcm.trellix.com/corporate/index?page=content&id=SB10405](https://kcm.trellix.com/corporate/index?page=content&id=SB10405)