Vulnerabilities > CVE-2022-4326 - Improper Preservation of Permissions vulnerability in Trellix Endpoint Security

047910
CVSS 6.0 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
trellix
CWE-281

Summary

Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality.

Vulnerable Configurations

Part Description Count
Application
Trellix
1
OS
Microsoft
1

Common Weakness Enumeration (CWE)