CVE-2023-3314: Trellix Enterprise Security Manager

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain elevation of system privileges.

Affected products

  • Trellix Enterprise Security Manager: before 11.6.7 (fixed in 11.6.7)

Published 2023-07-03. Last modified 2026-06-17.