Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0400


The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.


Published

2023-02-02T09:15:08.503

Last Modified

2024-11-21T07:37:07.010

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-670
  • Type: Primary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application trellix data_loss_prevention < 11.10.0 Yes
Operating System microsoft windows - No

References