CVE-2023-0978

A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:advanced_threat_defense:*:*:*:*:*:*:*:*
cpe:2.3:a:trellix:intelligent_sandbox:5.0:*:*:*:*:*:*:*
cpe:2.3:a:trellix:intelligent_sandbox:5.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-03-13 14:15

Updated : 2023-11-07 04:02


NVD link : CVE-2023-0978

Mitre link : CVE-2023-0978

CVE.ORG link : CVE-2023-0978


JSON object : View

Products Affected

trellix

  • intelligent_sandbox

mcafee

  • advanced_threat_defense
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')