CVE-2022-44653: Trend Micro Apex One Security Agent Directory Traversal Local Privilege Escalation Vulnerability
A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Apex One Client Plug-in Service Manager. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44653?
CVE-2022-44653 is a vulnerability that allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent.
How severe is CVE-2022-44653?
CVE-2022-44653 has a severity score of 7.8 (high).
How can an attacker exploit CVE-2022-44653?
To exploit CVE-2022-44653, an attacker must first obtain the ability to execute low-privileged code on the target system.
Which software versions are affected by CVE-2022-44653?
CVE-2022-44653 affects Trend Micro Apex One Security Agent versions up to and including 14.0.11789 and 2019.
How can I fix CVE-2022-44653?
To fix CVE-2022-44653, it is recommended to update to the latest version of Trend Micro Apex One Security Agent.