CVE-2022-40143: Trend Micro Apex One Link Following Local Privilege Escalation Vulnerability
A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbitrary code with elevated privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-40143.
What is the title of this vulnerability?
The title of this vulnerability is Trend Micro Apex One Link Following Local Privilege Escalation Vulnerability.
What is the severity of CVE-2022-40143?
The severity of CVE-2022-40143 is high with a severity value of 7.3.
Which software is affected by this vulnerability?
Trend Micro Apex One, Trend Micro Apex Central, Trend Micro Trend Micro Apex One and Worry-Free Business Security are affected by this vulnerability.
How can an attacker exploit this vulnerability?
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.