An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). 
The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services.
                
            References
                    | Link | Resource | 
|---|---|
| https://kcm.trellix.com/corporate/index?page=content&id=SB10404 | Patch Vendor Advisory | 
| https://kcm.trellix.com/corporate/index?page=content&id=SB10404 | Patch Vendor Advisory | 
Configurations
                    History
                    21 Nov 2024, 08:17
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 4.4 | 
| References | () https://kcm.trellix.com/corporate/index?page=content&id=SB10404 - Patch, Vendor Advisory | 
14 Jul 2023, 14:43
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-428 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.8 | 
| References | (MISC) https://kcm.trellix.com/corporate/index?page=content&id=SB10404 - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:trellix:move:*:*:*:*:*:windows:*:* | 
03 Jul 2023, 13:02
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-07-03 08:15
Updated : 2024-11-21 08:17
NVD link : CVE-2023-3438
Mitre link : CVE-2023-3438
CVE.ORG link : CVE-2023-3438
JSON object : View
Products Affected
                trellix
- move
CWE
                
                    
                        
                        CWE-428
                        
            Unquoted Search Path or Element
