First published: Wed Sep 28 2022(Updated: )
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This vulnerability is similar to, but not identical to CVE-2022-40707.
Credit: security@trendmicro.com security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Deep Security | =20.0 | |
All of | ||
Any of | ||
Trendmicro Deep Security Agent | =20.0 | |
Trendmicro Deep Security Agent | =20.0-update1337 | |
Trendmicro Deep Security Agent | =20.0-update1559 | |
Trendmicro Deep Security Agent | =20.0-update158 | |
Trendmicro Deep Security Agent | =20.0-update167 | |
Trendmicro Deep Security Agent | =20.0-update1681 | |
Trendmicro Deep Security Agent | =20.0-update173 | |
Trendmicro Deep Security Agent | =20.0-update180 | |
Trendmicro Deep Security Agent | =20.0-update182 | |
Trendmicro Deep Security Agent | =20.0-update1822 | |
Trendmicro Deep Security Agent | =20.0-update183 | |
Trendmicro Deep Security Agent | =20.0-update1876 | |
Trendmicro Deep Security Agent | =20.0-update190 | |
Trendmicro Deep Security Agent | =20.0-update198 | |
Trendmicro Deep Security Agent | =20.0-update2009 | |
Trendmicro Deep Security Agent | =20.0-update208 | |
Trendmicro Deep Security Agent | =20.0-update213 | |
Trendmicro Deep Security Agent | =20.0-update2204 | |
Trendmicro Deep Security Agent | =20.0-update223 | |
Trendmicro Deep Security Agent | =20.0-update224 | |
Trendmicro Deep Security Agent | =20.0-update2419 | |
Trendmicro Deep Security Agent | =20.0-update2593 | |
Trendmicro Deep Security Agent | =20.0-update2740 | |
Trendmicro Deep Security Agent | =20.0-update2921 | |
Trendmicro Deep Security Agent | =20.0-update3165 | |
Trendmicro Deep Security Agent | =20.0-update3288 | |
Trendmicro Deep Security Agent | =20.0-update3445 | |
Trendmicro Deep Security Agent | =20.0-update3530 | |
Trendmicro Deep Security Agent | =20.0-update3771 | |
Trendmicro Deep Security Agent | =20.0-update3964 | |
Trendmicro Deep Security Agent | =20.0-update4185 | |
Trendmicro Deep Security Agent | =20.0-update4416 | |
Trendmicro Deep Security Agent | =20.0-update4726 | |
Trendmicro Deep Security Agent | =20.0-update4959 | |
Trendmicro Deep Security Agent | =20.0-update5137 | |
Trendmicro Deep Security Agent | =20.0-update877 | |
Microsoft Windows | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40708 is a vulnerability that allows local attackers to disclose sensitive information on affected installations of Trend Micro Deep Security.
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
CVE-2022-40708 has a severity score of 4.4, classified as medium.
Trend Micro Deep Security version 20.0 is affected by this vulnerability.
To fix CVE-2022-40708, it is recommended to apply the latest security updates provided by Trend Micro.