CVE-2022-40709: Trend Micro Deep Security Out-Of-Bounds Read Information Disclosure Vulnerability
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This vulnerability is similar to, but not identical to CVE-2022-40707 and 40708.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40709?
CVE-2022-40709 is a vulnerability in Trend Micro Deep Security that allows local attackers to disclose sensitive information.
How can this vulnerability be exploited?
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
What is the severity of CVE-2022-40709?
CVE-2022-40709 has a severity rating of medium, with a CVSS score of 4.4.
Which versions of Trend Micro Deep Security are affected?
Trend Micro Deep Security version 20.0 is affected by CVE-2022-40709.
How can I fix CVE-2022-40709?
To fix CVE-2022-40709, it is recommended to apply the latest security updates provided by Trend Micro.