CVE-2022-40142: Trend Micro Apex One Security Agent Link Following Local Privilege Escalation Vulnerability
A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service agents could allow a local attacker to create a writable folder in an arbitrary location and escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40142?
CVE-2022-40142 is a vulnerability that allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent.
How can the vulnerability be exploited?
In order to exploit CVE-2022-40142, an attacker must first obtain the ability to execute low-privileged code on the target system.
What is the severity of CVE-2022-40142?
CVE-2022-40142 has a severity rating of 7.8 (high).
Which products are affected by CVE-2022-40142?
Trend Micro Apex One, Trend Micro Apex Central, Trend Micro Trend Micro Apex One and Worry-Free Business Security are affected by CVE-2022-40142.
How can I fix the CVE-2022-40142 vulnerability?
To fix the CVE-2022-40142 vulnerability, it is recommended to apply the latest security updates provided by Trend Micro.