CVE-2024-4176: Trellix Xconsole
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted malicious links to the EDR XConsole end user.
Affected products
- Trellix Xconsole: up to and including 2024-05-17
Published 2024-06-13. Last modified 2026-06-17.