CVE-2024-0311 describes a vulnerability in Skyhigh Client Proxy where a malicious insider can bypass the enforced security policy without requiring a valid release code. This allows the user to circumvent controls intended to restrict or monitor network traffic, potentially undermining organizational security policies.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2024-0311, a local privilege/policy bypass in the Skyhigh Security (formerly McAfee/Trellix) Client Proxy for Windows. The exploit consists of a Visual Studio solution with two main components: a shellcode injector (Injct) and an optional DLL (InjmeDLL). The primary exploit is implemented in 'Injct/Injct.cpp', which injects custom x64 shellcode (defined in 'shellcode/loadlibrary.asm' and compiled into 'Injct/shellcode.c') into a running instance of SCPBypass.exe. The shellcode opens the named pipe '\\.\pipe\MCPTrayPipe0' and writes the string '1440 ' to it, causing the proxy client to enter bypass mode for 24 hours. This bypasses policy enforcement even if the pipe is protected, as the check is based on the process writing to the pipe. The exploit is operational as a PoC, requiring local access and the ability to inject into a trusted process. The repository is well-structured for Visual Studio, with clear separation of injector, shellcode, and optional DLL components. No network endpoints or remote attack vectors are present; the attack is purely local and targets Windows systems running the vulnerable proxy client.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.