A code injection vulnerability in Trellix ENS 10.7.0 April 2023...
Vulnerability Description
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-3665
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- De Laurentis Vito
Affected Vendor
Trellix
View all reports →