A code injection vulnerability in Trellix ENS 10.7.0...
High severity
Unreviewed
Published
Oct 4, 2023
to the GitHub Advisory Database
•
Updated Apr 11, 2024
Description
Published by the National Vulnerability Database
Oct 4, 2023
Published to the GitHub Advisory Database
Oct 4, 2023
Last updated
Apr 11, 2024
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables,
leading to denial of service and or the execution of arbitrary code.
References