CVE-2022-4326

MEDIUM

Trellix Endpoint Agent <V35.31.22 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality.

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 7.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-281
Status published
Products (1)
trellix/endpoint_security < 35.31.22
Published Dec 16, 2022
Tracked Since Feb 18, 2026