Skip to main content

Vendor archive

trellix CVEs

Beta · best-effort

32 CVEs tagged to vendor trellix1 Critical, 10 High, 19 Medium, 0 Low, 2 Unrated.

CVE-2025-14963

Published Feb 24, 2026

A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Br…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-3773

Published Jun 26, 2025

A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-3771

Published Jun 26, 2025

A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, wh…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3722

Published Jun 26, 2025

A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2024-11482

Published Nov 29, 2024

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11481

Published Nov 29, 2024

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP back…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4176

Published Jun 13, 2024

An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A mal…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6072

Published Feb 13, 2024

A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0213

Published Jan 9, 2024

A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through explo…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6071

Published Nov 30, 2023

An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on th…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6070

Published Nov 29, 2023

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configurati…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5607

Published Nov 27, 2023

An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises ePO servers, prior to version 8.4.0 could…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6119

Published Nov 16, 2023

An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to files that usually require a h…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3665

Published Oct 4, 2023

A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to d…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4814

Published Sep 14, 2023

A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3314

Published Jul 3, 2023

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process exe…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3438

Published Jul 3, 2023

An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). The misconfiguration allowed an unauthori…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3313

Published Jul 3, 2023

An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1388

Published Jun 7, 2023

A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, resulting in the service becomin…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0976

Published Jun 7, 2023

A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder. The malicious…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 32 CVEsPage 1 of 2