First published: Sat Apr 09 2022(Updated: )
A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Antivirus For Mac | <=11.5 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27883 is a vulnerability in Trend Micro Antivirus for Mac that allows local attackers to escalate privileges on affected installations.
To exploit CVE-2022-27883, an attacker must first obtain the ability to execute low-privileged code on the target system.
The severity level of CVE-2022-27883 is high.
To fix CVE-2022-27883, update Trend Micro Antivirus for Mac to version 11.5 or later.
You can find more information about CVE-2022-27883 at the following references: - [Trend Micro Help Center](https://helpcenter.trendmicro.com/en-us/article/tmka-10978) - [Zero Day Initiative Advisory](https://www.zerodayinitiative.com/advisories/ZDI-22-546/)