QID 379127
Date Published: 2024-01-04
QID 379127: Trellix Endpoint Security (ENS) Multiple Vulnerabilities (SB10405)
Trellix Endpoint Security (ENS) protects the productivity of users with a common service layer and our new anti-malware core engine that helps reduce the amount of resources and power required by a user's system.
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code.
Affected versions:
ENS 10.7.0 April 2023 and earlier
QID Detection Logic(Authenticated):
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit.
Successful exploitation could allow a local user to disable the ENS AMSI component via environment variables, leading to denial of service or the execution of arbitrary code vulnerability
CVEs related to QID 379127
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SB10405 |
|