Description

Trellix has issued a critical update for its Enterprise Security Manager (ESM) to address two high-severity vulnerabilities CVE-2024-11481 (CVSS 8.2) and CVE-2024-11482 (CVSS 9.8) that impact version 11.6.10. These vulnerabilities could allow unauthorized access and remote code execution, posing serious risks to organizations. Trellix urges users to upgrade to version 11.6.13 immediately to safeguard against potential exploitation. CVE-2024-11481 allows unauthenticated attackers to exploit the internal Snowservice API due to flaws in path traversal handling, improper forwarding to an AJP backend, and weak authentication controls. Successful exploitation could expose sensitive data or cause service interruptions. CVE-2024-11482 is even more critical, as it enables attackers to execute arbitrary commands with root-level privileges, potentially resulting in a complete system takeover. Both vulnerabilities stem from inadequate access control mechanisms, threatening the confidentiality, integrity, and availability of affected systems. To mitigate these risks, Trellix has released ESM version 11.6.13, which includes fixes for both vulnerabilities. Organizations using the impacted versions are strongly encouraged to apply the update without delay to ensure their systems remain secure. Prioritizing this update is essential to protect enterprise environments from potential attacks.