First published: Thu Feb 24 2022(Updated: )
A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local attacker to create a mount point and leverage this for arbitrary folder deletion, leading to escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Apex One | ||
Trendmicro Apex One | ||
Trendmicro Apex One | =2019 | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Trendmicro Worry-free Business Security Services | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24680 is a security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1, and Trend Micro Worry-Free Business Security Services agents.
CVE-2022-24680 allows a local attacker to create a mount point and escalate their privileges on affected Trend Micro products.
CVE-2022-24680 affects Trend Micro Apex One versions up to 2019 and Trend Micro Worry-Free Business Security 10.0 SP1.
CVE-2022-24680 has a severity rating of 7.8 (high).
To mitigate CVE-2022-24680, apply the necessary patches or updates provided by Trend Micro and follow their recommended security best practices.