CVE-2023-0978

A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:advanced_threat_defense:*:*:*:*:*:*:*:*
cpe:2.3:a:trellix:intelligent_sandbox:5.0:*:*:*:*:*:*:*
cpe:2.3:a:trellix:intelligent_sandbox:5.2:*:*:*:*:*:*:*

History

21 Nov 2024, 07:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.7
v2 : unknown
v3 : 6.4
References () https://kcm.trellix.com/corporate/index?page=content&id=SB10397 - Vendor Advisory () https://kcm.trellix.com/corporate/index?page=content&id=SB10397 - Vendor Advisory

07 Nov 2023, 04:02

Type Values Removed Values Added
Summary A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack

Information

Published : 2023-03-13 14:15

Updated : 2024-11-21 07:38


NVD link : CVE-2023-0978

Mitre link : CVE-2023-0978

CVE.ORG link : CVE-2023-0978


JSON object : View

Products Affected

trellix

  • intelligent_sandbox

mcafee

  • advanced_threat_defense
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')