VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating system.
2023-02-22T00:15:11.570
2025-03-17T19:15:17.847
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | carbon_black_app_control | < 8.7.8 | Yes |
Application | vmware | carbon_black_app_control | < 8.8.6 | Yes |
Application | vmware | carbon_black_app_control | < 8.9.4 | Yes |
Operating System | microsoft | windows | - | No |