CVE-2022-30687: Trend Micro Maximum Security Link Following Arbitrary File Deletion Vulnerability
This vulnerability allows local attackers to delete arbitrary files on affected installations of Trend Micro Maximum Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of the Secure Erase feature. The issue results from the lack of proper validation of a user-supplied link prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM.
Other sources
Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the product's secure erase feature to delete arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30687?
CVE-2022-30687 is a vulnerability in Trend Micro Maximum Security that allows local attackers to delete arbitrary files on affected installations.
How severe is CVE-2022-30687?
CVE-2022-30687 has a severity rating of 7.1, which is considered high.
Which software is affected by CVE-2022-30687?
Trend Micro Maximum Security versions 17.7 are affected by CVE-2022-30687.
How can an attacker exploit CVE-2022-30687?
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit CVE-2022-30687.
Is Microsoft Windows vulnerable to CVE-2022-30687?
No, Microsoft Windows is not vulnerable to CVE-2022-30687.