- Description
- A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) was leveraged to gain access to the critical Windows process memory lsass.exe (Local Security Authority Subsystem Service). The fekern.sys is a driver file associated with the HX Agent (used in all existing HX Agent versions). The vulnerable driver installed in a product or a system running a fully functional HX Agent is, itself, not exploitable as the product’s tamper protection restricts the ability to communicate with the driver to only the Agent’s processes.
- Source
- trellixpsirt@trellix.com
- NVD status
- Analyzed
- Products
- endpoint_security
CVSS 4.0
- Type
- Secondary
- Base score
- 6.2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- trellixpsirt@trellix.com
- CWE-20
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
CVE-2025-14963 A vulnerability identified in the Trellix HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privilege… https://t.co/08rDr9O8rL
@CVEnew
25 Feb 2026
135 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-14963 Local Privilege Escalation in Trellix HX Agent Driver fekern.sys https://t.co/00C9dvQ6TF Vulnerability Alert Subscriptions: https://t.co/hrQhy5uz4x
@VulmonFeeds
24 Feb 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:trellix:endpoint_security:*:*:*:*:*:*:*:*",
"matchCriteriaId": "52DECB52-A903-466A-8F0A-89544E1AF8C6",
"versionEndIncluding": "34.0.0",
"versionStartIncluding": "30.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:trellix:endpoint_security:35.31.0-37:*:*:*:*:*:*:*",
"matchCriteriaId": "DB7C7EB0-B5E5-42D4-97E3-71F0A1E0D2B1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:trellix:endpoint_security:36.30.0-17:*:*:*:*:*:*:*",
"matchCriteriaId": "E6EE0927-FA12-481E-9F4C-491091576A03",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]