An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.  This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 23 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: trellix
Published: 2022-11-30T08:29:29.242Z
Updated: 2025-04-23T19:28:30.917Z
Reserved: 2022-11-04T09:51:23.470Z
Link: CVE-2022-3859
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-03T01:20:58.790Z
 NVD
                        NVD
                    Status : Modified
Published: 2022-11-30T09:15:08.977
Modified: 2024-11-21T07:20:22.817
Link: CVE-2022-3859
 Redhat
                        Redhat
                    No data.