ZDI-22-620: Trend Micro HouseCall for Home Networks Uncontrolled Search Path Element Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro HouseCall for Home Networks. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the log4j scanner. The process loads a file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-22-620?
The ZDI-22-620 vulnerability is classified as a moderate severity privilege escalation vulnerability.
How do I fix ZDI-22-620?
To fix the ZDI-22-620 vulnerability, users should update Trend Micro HouseCall for Home Networks to the latest version provided by the vendor.
Who is affected by ZDI-22-620?
ZDI-22-620 affects installations of Trend Micro HouseCall for Home Networks where low-privileged code execution is possible.
Can ZDI-22-620 be exploited remotely?
No, ZDI-22-620 cannot be exploited remotely; an attacker must have local access to the system.
What is the potential impact of ZDI-22-620?
The potential impact of ZDI-22-620 includes unauthorized privilege escalation, allowing an attacker to gain higher-level access to the system.