CVE-2025-3773: Trellix System Information Reporter

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.

Affected products

  • Trellix System Information Reporter: up to and including 1.0.3

Published 2025-06-26. Last modified 2026-06-17.