VYPR
Medium severity6.3NVD Advisory· Published Jun 7, 2023· Updated Jun 17, 2026

CVE-2023-0976

CVE-2023-0976

Description

A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder. The malicious file is executed by running the TA deployment feature located in the System Tree.

Affected products

3
  • Trellix/Agent2 versions
    cpe:2.3:a:trellix:agent:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:trellix:agent:*:*:*:*:*:*:*:*range: <5.7.9
    • (no CPE)range: 5.7.8
  • Range: <5.7.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.