TAN-2026-022
Tanium addressed an unauthorized code execution vulnerability in Enforce.
Severity: High
Base Score: 7.0
Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact
This vulnerability could allow an attacker with access to a system running the Tanium Client to achieve local privilege escalation when a maliciously-named file already present in antivirus quarantine is processed during a remediation action.
Products Affected
2025H1 Release:
- Enforce prior to Update 24 (v2.9 to v2.9.718)
2025H2 Release:
- Enforce prior to Update 14 (v2.10 to v2.10.760)
2026H1 Release:
- Enforce prior to Update 7 (v3.0 to v3.0.346)
Available Updates
2025H1 Release:
- Update 24 (Enforce v2.9.718) and later
2025H2 Release:
- Update 14 (Enforce v2.10.760) and later
2026H1 Release:
- Update 7 (Enforce v3.0.346) and later
Workaround and Mitigations
None.
Acknowledgements
None.