CVE-2022-38764: Trend Micro HouseCall Incorrect Permission Assignment Privilege Escalation Vulnerability
A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissive folder om the product installer.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro HouseCall. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from incorrect permissions set on product folders created by the installer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38764?
CVE-2022-38764 is classified as a high severity vulnerability due to its ability to allow local privilege escalation.
How do I fix CVE-2022-38764?
To address CVE-2022-38764, update Trend Micro HouseCall to version 1.62.1.1134 or later, which contains the necessary patches.
Who is affected by CVE-2022-38764?
CVE-2022-38764 affects installations of Trend Micro HouseCall version 1.62.1.1133 and below on Windows operating systems.
What type of attack can exploit CVE-2022-38764?
CVE-2022-38764 can be exploited by local attackers to escalate their privileges on affected systems.
Is there a workaround for CVE-2022-38764?
Currently, there are no documented workarounds for CVE-2022-38764 other than upgrading to the patched version.