CVE-2022-41748: Medium severity trendmicro Apex One vulnerability
A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative credentials to bypass certain elements of the product's anti-tampering mechanisms on affected installations. Please note: an attacker must first obtain administrative credentials on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-41748.
What is the affected software?
The affected software includes Trend Micro Apex One and Worry-Free Business Security versions 2019 and saas.
What is the severity of CVE-2022-41748?
The severity of CVE-2022-41748 is medium with a CVSS score of 6.7.
How can a local attacker exploit this vulnerability?
A local attacker with administrative credentials can exploit this vulnerability to bypass certain elements of the product's anti-tampering mechanisms.
Is Microsoft Windows affected by this vulnerability?
No, Microsoft Windows is not vulnerable to CVE-2022-41748.