CVE-2022-40707: Trend Micro Deep Security Out-Of-Bounds Read Information Disclosure Vulnerability
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This vulnerability is similar to, but not identical to CVE-2022-40708.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40707?
CVE-2022-40707 is a vulnerability that allows local attackers to disclose sensitive information on affected installations of Trend Micro Deep Security.
How severe is CVE-2022-40707?
CVE-2022-40707 has a severity rating of medium, with a CVSS score of 4.4.
What is the affected software for CVE-2022-40707?
The affected software for CVE-2022-40707 is Trend Micro Deep Security version 20.0.
How can CVE-2022-40707 be exploited?
To exploit CVE-2022-40707, an attacker must first obtain the ability to execute low-privileged code on the target system.
How can I fix CVE-2022-40707?
To fix CVE-2022-40707, it is recommended to update to a patched version of Trend Micro Deep Security.