A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack
References
Link | Resource |
---|---|
https://kcm.trellix.com/corporate/index?page=content&id=SB10397 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-03-13 07:15
Updated : 2023-03-16 21:03
NVD link : CVE-2023-0978
Mitre link : CVE-2023-0978
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
mcafee
- advanced_threat_defense
trellix
- intelligent_sandbox