CVE-2023-52092: Trend Micro Apex One Link Following Local Privilege Escalation Vulnerability
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Damage Cleanup Engine. By creating a junction, an attacker can abuse a driver to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52092?
CVE-2023-52092 has been classified as a high severity vulnerability.
How do I fix CVE-2023-52092?
To resolve CVE-2023-52092, update Trend Micro Apex One to the latest version or apply the recommended security patches.
Who is affected by CVE-2023-52092?
CVE-2023-52092 affects installations of Trend Micro Apex One, particularly those versions prior to 14.0.12849.
What type of vulnerability is CVE-2023-52092?
CVE-2023-52092 is a local privilege escalation vulnerability.
What must an attacker do to exploit CVE-2023-52092?
An attacker must first gain the ability to execute low-privileged code on the affected system to exploit CVE-2023-52092.