CVE-2024-36306: Trend Micro Apex One Damage Cleanup Engine Link Following Denial-of-Service Vulnerability
A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine could allow a local attacker to create a denial-of-service condition on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Damage Cleanup Engine, which runs within the Trend Micro Common Client Real-time Scan Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36306?
CVE-2024-36306 has a medium severity rating due to its potential to enable denial-of-service conditions.
How do I fix CVE-2024-36306?
To fix CVE-2024-36306, users should update to the latest patched version of Trend Micro Apex One.
What systems are affected by CVE-2024-36306?
CVE-2024-36306 affects Trend Micro Apex One and Apex One as a Service installations below version 14.0.0.12980.
Can CVE-2024-36306 be exploited remotely?
No, CVE-2024-36306 requires local access to the system for exploitation.
What type of vulnerability is CVE-2024-36306?
CVE-2024-36306 is categorized as a link following vulnerability.