Show filters
242 Total Results
Displaying 51-60 of 242
Sort by:
Attacker Value
Unknown

CVE-2022-38777

Disclosure Date: February 08, 2023 (last updated October 08, 2023)
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Attacker Value
Unknown

CVE-2022-38775

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Attacker Value
Unknown

CVE-2022-38774

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
Attacker Value
Unknown

CVE-2022-4326

Disclosure Date: December 16, 2022 (last updated November 08, 2023)
Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality.
Attacker Value
Unknown

CVE-2022-28887

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.
Attacker Value
Unknown

CVE-2022-28886

Disclosure Date: September 23, 2022 (last updated October 08, 2023)
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine
Attacker Value
Unknown

CVE-2022-1700

Disclosure Date: September 12, 2022 (last updated October 08, 2023)
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Security with DLP enabled, and Cloud Security Gateway prior to June 20, 2022. The XML parser in the Policy Engine was found to be improperly configured to support external entities and external DTD (Document Type Definitions), which can lead to an XXE attack. This issue affects: Forcepoint Data Loss Prevention (DLP) versions prior to 8.8.2. Forcepoint One Endpoint (F1E) with Policy Engine versions prior to 8.8.2. Forcepoint Web Security Content Gateway versions prior to 8.5.5. Forcepoint Email Security with DLP enabled versions prior to 8.5.5. Forcepoint Cloud Security Gateway prior to June 20, 2022.
Attacker Value
Unknown

CVE-2022-28884

Disclosure Date: September 06, 2022 (last updated October 08, 2023)
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine.
Attacker Value
Unknown

CVE-2022-28883

Disclosure Date: August 23, 2022 (last updated October 08, 2023)
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack function crashes. This can lead to a possible scanning engine crash. The exploit can be triggered remotely by an attacker.
Attacker Value
Unknown

CVE-2022-28882

Disclosure Date: August 23, 2022 (last updated October 08, 2023)
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go into an infinite loop when unpacking PE files. This eventually leads to scanning engine crash. The exploit can be triggered remotely by an attacker.