First published: Mon Sep 19 2022(Updated: )
A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbitrary code with elevated privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Apex One | ||
Trendmicro Apex One | =2019 | |
Microsoft Windows | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-40143.
The title of this vulnerability is Trend Micro Apex One Link Following Local Privilege Escalation Vulnerability.
The severity of CVE-2022-40143 is high with a severity value of 7.3.
Trend Micro Apex One, Trend Micro Apex Central, Trend Micro Trend Micro Apex One and Worry-Free Business Security are affected by this vulnerability.
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.