A critical vulnerability has been addressed by Trellix in its Enterprise Security Manager (ESM) that could potentially expose the internal Snowservice API to unauthorized access.
The flaw, discovered in ESM version 11.6.10, has raised concerns among cybersecurity experts due to its potential for exploitation.
The vulnerability, which allows unauthenticated access to the internal Snowservice API, presents multiple security risks.
These include improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and a lack of authentication for accessing internal API endpoints.
Researchers at Trellix observed that such vulnerabilities could potentially be exploited by malicious actors to gain unauthorized access to sensitive information or compromise system integrity.
Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar
In response to this security threat, Trellix has released version 11.6.13 of the Enterprise Security Manager, which includes critical security updates and feature enhancements.
This latest release is part of Trellix’s ongoing efforts to improve the security and functionality of their products.
Key updates in ESM 11.6.13 include:-
The CERT-Bund of the BSI has classified these vulnerabilities with a maximum CVSS value of 9.8, indicating a critical risk level. They warn that these flaws could allow attackers to bypass security measures, emphasizing the importance of applying the update promptly.
In addition to security fixes, ESM 11.6.13 introduces new features and improvements:
Trellix strongly recommends that all users upgrade to ESM 11.6.13 as soon as possible to mitigate potential security risks. The company emphasizes that this update is crucial for all environments and should be applied at the earliest convenience.
Timely security updates like this one from Trellix play a critical role in maintaining the integrity and security of enterprise systems.
Organizations using Trellix Enterprise Security Manager are advised to review their current version and plan for immediate upgrades to ensure their systems remain protected against the latest known vulnerabilities.
Analyse Advanced Malware & Phishing Analysis With ANY.RUN Black Friday Deals : Get up to 3 Free Licenses.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…