CVE-2022-30523: Trend Micro Password Manager Link Following Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Password Manager. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Trend Micro Password Manager Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Other sources
Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow a low privileged local attacker to delete the contents of an arbitrary folder as SYSTEM which can then be used for privilege escalation on the affected machine.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30523?
CVE-2022-30523 has a severity rating that indicates it allows local privilege escalation.
How do I fix CVE-2022-30523?
To fix CVE-2022-30523, update Trend Micro Password Manager to the latest version available.
Who is affected by CVE-2022-30523?
CVE-2022-30523 affects users of Trend Micro Password Manager version prior to 5.0.0.1270.
What type of attacks does CVE-2022-30523 enable?
CVE-2022-30523 allows local attackers to escalate their privileges on the affected systems.
What is the nature of the flaw in CVE-2022-30523?
The flaw in CVE-2022-30523 exists due to improper handling of low-privileged code execution.