CVE-2022-40710: Trend Micro Deep Security Link Following Local Privilege Escalation Vulnerability
A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40710?
CVE-2022-40710 is a vulnerability in Trend Micro Deep Security that allows local attackers to escalate privileges on affected installations.
How severe is CVE-2022-40710?
CVE-2022-40710 has a severity rating of 7.8 (high).
What is the affected software?
The affected software is Trend Micro Deep Security version 20.0 (long-term support).
How can this vulnerability be exploited?
To exploit CVE-2022-40710, an attacker must first obtain the ability to execute low-privileged code on the target system.
Is there a fix available for CVE-2022-40710?
Yes, it is recommended to update to the latest version of Trend Micro Deep Security to mitigate this vulnerability.