CVE-2022-40708: Trend Micro Deep Security Out-Of-Bounds Read Information Disclosure Vulnerability
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This vulnerability is similar to, but not identical to CVE-2022-40707.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40708?
CVE-2022-40708 is a vulnerability that allows local attackers to disclose sensitive information on affected installations of Trend Micro Deep Security.
How can this vulnerability be exploited?
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
What is the severity of CVE-2022-40708?
CVE-2022-40708 has a severity score of 4.4, classified as medium.
Which software versions are affected by CVE-2022-40708?
Trend Micro Deep Security version 20.0 is affected by this vulnerability.
How do I fix CVE-2022-40708?
To fix CVE-2022-40708, it is recommended to apply the latest security updates provided by Trend Micro.