Endpoint Security (EDR und XDR)

Schwachstellen bei Trellix: jede Meldung, die die Register seinen Produkten zuordnen

Kurz gesagt

52 Schwachstellenmeldungen in diesem Bestand sind Produkten von Trellix zugeordnet. Sie reichen von Oktober 2022 bis Juli 2026. Keine davon steht im CISA-Katalog bekannt ausgenutzter Schwachstellen. Jeder Eintrag unten verlinkt auf das Register, das ihn veröffentlicht hat.

Zugeordnet

52

an ein benanntes Produkt gebunden

Aktiv ausgenutzt

0

im CISA-Katalog geführt

Als kritisch eingestuft

1

Einstufung des Registers

Zuletzt geprüft

17. Juli 2026

Quellen neu abgefragt

Warum diese Liste kürzer ist als ein CVE-Spiegel

Die Register werden über Stichworte durchsucht, also liefert die Suche nach einem Firmennamen auch Meldungen zurück, die diesen Namen nur erwähnen. Ein Spiegel veröffentlicht sie mit. Diese Seite nicht: Ein Eintrag erscheint erst, wenn das Register selbst ihn an ein Produkt von Trellix bindet, über einen Verweis auf eine Adresse des Anbieters, über Trellix als die Stelle, die die CVE-Nummer vergeben hat, oder über die Liste der betroffenen Produkte.

0 Einträge haben diese Hürde nicht genommen und werden nicht angezeigt. Das ist der Unterschied, und er ist gewollt: Eine Seite, die die Schwachstelle eines anderen Unternehmens unter dieser Überschrift führt, ist auf die Art falsch, die am meisten kostet.

50 der 52 Einträge tragen einen CVSS-Basiswert aus dem Register. Wo keiner veröffentlicht ist, steht keiner, und geschätzt wird nichts.

Die vollständige Liste, bekannt ausgenutzte und neueste zuerst

Führen mehrere Register dieselbe Meldung, steht sie einmal da, mit einem Link auf jedes. So wird dieselbe Schwachstelle nicht doppelt gezählt. Einträge aus dem CISA-Katalog bekannt ausgenutzter Schwachstellen stehen oben, weil das der eine Hinweis auf dieser Seite ist, der ändert, was als Nächstes zu tun ist.

  • CVE-2026-12588mediumCVSS 6.014. Juli 2026

    An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console.

  • CVE-2025-7958highCVSS 7.126. Juni 2026

    A Code Injection vulnerability existed in Trellix Network Security CM and NX.

  • WID-SEC-2026-0538mediumCVSS 6.426. Feb. 2026

    Affected products: Trellix Endpoint Security

  • CVE-2025-14963mediumCVSS 6.224. Feb. 2026

    A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges.

  • WID-SEC-2025-2597highCVSS 8.814. Nov. 2025

    Affected products: Trellix Agent

  • WID-SEC-2025-1609lowCVSS 4.401. Okt. 2025

    Affected products: Trellix Endpoint Security, Absolute Secure Access

  • CVE-2025-0664mediumCVSS 6.721. Juli 2025

    A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library.

  • WID-SEC-2025-1429mediumCVSS 5.601. Juli 2025

    Affected products: Trellix Endpoint Security

  • CVE-2025-5967mediumCVSS 5.301. Juli 2025

    A stored cross-site scripting vulnerability in ENS HX 10.0.4 allows a malicious user to inject arbitrary HTML into the ENS HX Malware Scan Name field, resulting in the exposure of sensitive…

  • CVE-2025-3771highCVSS 7.126. Juni 2025

    A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can…

  • CVE-2025-377326. Juni 2025

    A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in…

  • CVE-2025-372226. Juni 2025

    A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System…

  • WID-SEC-2025-0872mediumCVSS 6.523. Apr. 2025

    Affected products: Trellix Endpoint Security

  • CVE-2025-0618mediumCVSS 6.523. Apr. 2025

    A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a specially-crafted tamper protection event to the HX service to trigger an…

  • CVE-2025-0617mediumCVSS 5.929. Jan. 2025

    An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console.

  • WID-SEC-2024-3738mediumCVSS 5.420. Dez. 2024

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2024-3673mediumCVSS 7.311. Dez. 2024

    Affected products: Trellix Data Loss Prevention

  • CVE-2024-11482criticalCVSS 9.829. Nov. 2024

    A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

  • WID-SEC-2024-3538highCVSS 9.825. Nov. 2024

    Affected products: Trellix Enterprise Security Manager

  • WID-SEC-2024-1771mediumCVSS 7.307. Aug. 2024

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2024-1164highCVSS 8.017. Mai 2024

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2024-1085mediumCVSS 7.310. Mai 2024

    Affected products: Trellix Data Loss Prevention

  • CVE-2023-6072mediumCVSS 4.613. Feb. 2024

    A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary…

  • WID-SEC-2024-0061mediumCVSS 6.111. Jan. 2024

    Affected products: Trellix Endpoint Security

  • WID-SEC-2024-0033highCVSS 8.210. Jan. 2024

    Affected products: Trellix Agent

  • CVE-2024-0213highCVSS 8.209. Jan. 2024

    A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a…

  • CVE-2024-0206highCVSS 7.109. Jan. 2024

    A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of…

  • WID-SEC-2023-3026highCVSS 8.129. Nov. 2023

    Affected products: Trellix Enterprise Security Manager

  • WID-SEC-2023-2963highCVSS 8.017. Nov. 2023

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2023-2732mediumCVSS 7.324. Okt. 2023

    Affected products: Trellix Data Loss Prevention

  • WID-SEC-2023-2435mediumCVSS 5.525. Sept. 2023

    Affected products: Trellix Endpoint Security

  • WID-SEC-2023-2360mediumCVSS 6.215. Sept. 2023

    Affected products: Trellix Secure Web Gateway

  • WID-SEC-2023-2349mediumCVSS 7.114. Sept. 2023

    Affected products: Trellix Data Loss Prevention

  • WID-SEC-2023-1888mediumCVSS 5.426. Juli 2023

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2023-1598highCVSS 8.129. Juni 2023

    Affected products: Trellix Enterprise Security Manager

  • WID-SEC-2023-1387mediumCVSS 6.507. Juni 2023

    Affected products: Trellix Agent

  • CVE-2023-0976mediumCVSS 6.307. Juni 2023

    A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder.

  • CVE-2023-1388mediumCVSS 6.307. Juni 2023

    A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, resulting in the service becoming…

  • CVE-2023-0977mediumCVSS 6.703. Apr. 2023

    A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block…

  • CVE-2023-0975highCVSS 8.203. Apr. 2023

    A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it…

  • WID-SEC-2023-0817highCVSS 8.231. März 2023

    Affected products: Trellix Agent

  • CVE-2023-0978mediumCVSS 6.413. März 2023

    A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using…

  • WID-SEC-2023-0247mediumCVSS 6.706. Feb. 2023

    Affected products: Trellix Data Loss Prevention

  • CVE-2023-0400mediumCVSS 5.901. Feb. 2023

    The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.

  • WID-SEC-2023-0106mediumCVSS 6.118. Jan. 2023

    Affected products: Trellix Secure Web Gateway

  • CVE-2023-0221mediumCVSS 4.413. Jan. 2023

    Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using…

  • CVE-2022-4326mediumCVSS 5.516. Dez. 2022

    Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product…

  • CVE-2022-3859mediumCVSS 6.730. Nov. 2022

    An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.

  • CVE-2022-2188mediumCVSS 6.507. Nov. 2022

    Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory.

  • CVE-2022-3340mediumCVSS 5.904. Nov. 2022

    XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the…

  • CVE-2022-3338mediumCVSS 5.418. Okt. 2022

    An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack.

  • CVE-2022-3339mediumCVSS 5.418. Okt. 2022

    A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session…

Welche Register beigetragen haben

RegisterBetreiberEinträgeNeuester Eintrag
European Vulnerability DatabaseENISA, Europäische Union2714. Juli 2026
CERT-Bund SicherheitshinweiseBSI, Bundesrepublik Deutschland2526. Feb. 2026
National Vulnerability DatabaseNIST, US-Handelsministerium226. Juni 2026

Die Zahlen hier sind die rohen Registertreffer zu Trellix, vor der Zuordnung. Genau deshalb sind sie größer als die Liste darüber.

Fragen, die diese Seite beantwortet

Wie viele Schwachstellen hat Trellix?

52 Meldungen in diesem Bestand sind von einem Register einem Produkt von Trellix zugeordnet. Das ist nicht dasselbe wie die Zahl der Schwachstellen in den Produkten, und die kennt keine öffentliche Quelle. Es ist die Zahl dessen, was gefunden, offengelegt und veröffentlicht wurde, und die hängt daran, wie intensiv die Produkte geprüft werden und wie offen der Anbieter damit umgeht.

Werden Schwachstellen in Produkten von Trellix aktiv ausgenutzt?

Keiner der 52 Einträge steht im CISA-Katalog bekannt ausgenutzter Schwachstellen. Dieser Katalog ist nicht vollständig: Er führt, was CISA als ausgenutzt bestätigt hat. Dass ein Eintrag fehlt, ist deshalb kein Beleg dafür, dass nichts ausgenutzt wurde.

Warum zeigt diese Seite weniger CVEs zu Trellix als andere Seiten?

Weil eine Stichwortsuche nach einem Firmennamen auch Meldungen über Produkte anderer Unternehmen zurückgibt, die den Namen nur nebenbei erwähnen. Diese Seite lässt sie weg. 0 Registereinträge nennen Trellix, ohne eines seiner Produkte als betroffen zu benennen. Ein Spiegel, der sie mitführt, erzeugt eine längere Seite und eine falsche Zahl.

Woher stammen die Meldungen zu Trellix auf dieser Seite?

Aus diesen Registern: European Vulnerability Database, betrieben von ENISA, Europäische Union; CERT-Bund Sicherheitshinweise, betrieben von BSI, Bundesrepublik Deutschland; National Vulnerability Database, betrieben von NIST, US-Handelsministerium. Jeder Eintrag verlinkt zurück auf das Register, das ihn veröffentlicht hat, und trägt das Datum, das dieses Register nennt. Führen mehrere Register dieselbe Schwachstelle, steht sie einmal da, mit einem Link auf jedes, statt doppelt gezählt zu werden.

Heißt eine lange Liste, dass Trellix unsicher ist?

Nein. Ein Register hält fest, was Forschende gefunden und was der Anbieter offengelegt hat. Ein weit verbreitetes Produkt mit einem funktionierenden Offenlegungsprozess sammelt deshalb mehr Einträge als eines, das niemand prüft. Eine kurze Liste kann genauso gut für eine kleine Installationsbasis stehen oder für einen Anbieter, der wenig veröffentlicht. Diese Seite gibt den Bestand wieder und bewertet den Anbieter nicht, denn ob das für Sie tragbar ist, hängt an Ihrer Risikobereitschaft, Ihrem Compliance-Umfang und den Alternativen, die Sie abwägen.

Eine Liste von Meldungen ist noch keine Risikobewertung

Es zählt, welche davon die Komponenten betreffen, die Sie tatsächlich betreiben, in der Konfiguration, in der Sie sie betreiben, und ob das neben den Alternativen Ihrer engeren Auswahl tragbar ist. DecisionOS liest denselben Bestand an den Kriterien einer konkreten Entscheidung und liefert ein Memo, das vor Geschäftsführung und Revision standhält.

Der vollständige Bestand zu Trellix, samt Quellen und offenen Fragen

Trellix Schwachstellen: alle 52 Meldungen im Bestand, mit Quelle | DecisionOS by nexalign