QID 379127

Date Published: 2024-01-04

QID 379127: Trellix Endpoint Security (ENS) Multiple Vulnerabilities (SB10405)

Trellix Endpoint Security (ENS) protects the productivity of users with a common service layer and our new anti-malware core engine that helps reduce the amount of resources and power required by a user's system.

A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code.

Affected versions:
ENS 10.7.0 April 2023 and earlier
QID Detection Logic(Authenticated):
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit.

Successful exploitation could allow a local user to disable the ENS AMSI component via environment variables, leading to denial of service or the execution of arbitrary code vulnerability

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Install or update to Trellix Endpoint Security (ENS) 10.7.0 September 2023 Update For more details refer SB10405

    CVEs related to QID 379127

    Software Advisories
    Advisory ID Software Component Link
    SB10405 URL Logo kcm.trellix.com/corporate/index?page=content&id=SB10405