CVE-2023-3438

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
03/07/2023
Last modified:
14/07/2023

Description

<br /> An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). <br /> The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trellix:move:*:*:*:*:*:windows:*:* 4.10.0 (including)


References to Advisories, Solutions, and Tools