NA

CVE-2023-3438

Published: 03/07/2023 Updated: 14/07/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and previous versions Windows install service (mvagtsce.exe). The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services.

Vulnerable Product Search on Vulmon Subscribe to Product

trellix move