First published: Fri Jul 29 2022(Updated: )
A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for this issue has been deployed automatically via ActiveUpdate to customers in an updated Spyware pattern. Customers who are up-to-date on detection patterns are not required to take any additional steps to mitigate this issue.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Apex One | ||
Trendmicro Apex One | ||
Trendmicro Apex One | =2019 | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Trendmicro Worry-free Business Security Services | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36336 is a vulnerability that allows local attackers to escalate privileges on installations of Trend Micro Apex One Security Agent.
CVE-2022-36336 works by exploiting a flaw within Trend Micro Apex One Security Agent, which allows a local attacker to gain elevated privileges.
CVE-2022-36336 has a severity rating of 7.8 on the CVSS scale, indicating a high severity vulnerability.
CVE-2022-36336 affects installations of Trend Micro Apex One and Worry-Free Business Security.
To fix CVE-2022-36336, users should apply the necessary patches or updates provided by Trend Micro for Apex One and Worry-Free Business Security.