CVE-2022-44652: Trend Micro Apex One Improper Handling of Exceptional Conditions Local Privilege Escalation Vulnerability
An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the installer. The issue results from the lack of proper error handling when accessing files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44652?
CVE-2022-44652 is a vulnerability in Trend Micro Apex One Security Agent that allows local attackers to escalate privileges.
How severe is CVE-2022-44652?
The severity of CVE-2022-44652 is high, with a CVSS score of 7.8.
How can this vulnerability be exploited?
To exploit CVE-2022-44652, an attacker must first obtain the ability to execute low-privileged code on the target system.
Which software versions are affected by CVE-2022-44652?
Trend Micro Apex One versions 14.0.11789 and 2019 are affected by CVE-2022-44652.
Is there a fix for CVE-2022-44652?
Yes, Trend Micro has released a fix for CVE-2022-44652. It is recommended to update to the latest version of Trend Micro Apex One Security Agent.